CVE-2022-22912

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.

Apple property list parser/builder for Node.js and browsers — supports XML, binary (bplist), and OpenStep formats
GitHubGitHub
599