Prototype Pollution Vulnerability in Browserify-Shim by Thlorenz
CVE-2022-37623
9.8CRITICAL
What is CVE-2022-37623?
A prototype pollution vulnerability exists in the function resolveShims within resolve-shims.js of the Browserify-Shim library by Thlorenz. This vulnerability arises through improper handling of the shimPath variable. When exploited, it may allow attackers to manipulate the prototype of an object, potentially leading to unexpected behavior in applications that use this library. It is important for developers using Browserify-Shim to review the code and apply any necessary patches to mitigate the risks associated with this vulnerability.
