Description
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.
Remediation
References
https://github.com/TooTallNate/plist.js/issues/114
Related Vulnerabilities
CVE-2021-25329 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2018-20318 Vulnerability in maven package com.github.binarywang:weixin-java-common
CVE-2022-36083 Vulnerability in npm package jose
CVE-2018-16483 Vulnerability in npm package express-cart
CVE-2023-31580 Vulnerability in maven package com.networknt:light-oauth2