xmldom<=0.6.0 allows multiple root nodes in a DOM is regarded as a critical vulnerability scanned by GitHub Dependabot.
Impact
xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the childNodes collection of the Document, without reporting any error or throwing.
This breaks the assumption that there is only a single root node in the tree, which led to https://nvd.nist.gov/vuln/detail/CVE-2022-39299 and is a potential issue for dependents.
Patches
Update to @xmldom/xmldom@~0.7.7, @xmldom/xmldom@~0.8.4 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.4 (dist-tag next).
Please bump the version of xmldom, otherwise anyone depends on actions-secret-parser will be affected by this vulnerability.
xmldom<=0.6.0 allows multiple root nodes in a DOMis regarded as a critical vulnerability scanned by GitHub Dependabot.Impact
xmldom parses XML that is not well-formed because it contains multiple top level elements, and adds all root nodes to the childNodes collection of the Document, without reporting any error or throwing.
This breaks the assumption that there is only a single root node in the tree, which led to https://nvd.nist.gov/vuln/detail/CVE-2022-39299 and is a potential issue for dependents.
Patches
Update to @xmldom/xmldom@~0.7.7, @xmldom/xmldom@~0.8.4 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.4 (dist-tag next).
Please bump the version of
xmldom, otherwise anyone depends onactions-secret-parserwill be affected by this vulnerability.