CVE-2022-39357

Source
https://cve.org/CVERecord?id=CVE-2022-39357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39357
Aliases
Published
2022-10-26T00:00:00Z
Modified
2026-08-12T03:51:33Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Winter vulnerable to Prototype Pollution in Snowboard framework
Details

Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1321"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39357.json"
}
References

Affected packages

Git / github.com/wintercms/winter

Affected ranges

Type
GIT
Repo
https://github.com/wintercms/winter
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.1.8"
        },
        {
            "fixed": "1.1.10"
        },
        {
            "introduced": "= 1.2.0"
        },
        {
            "last_affected": "= 1.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.8
1.1.9
1.2.0
= 1.*
= 1.2.0
v1.*
v1.1.8
v1.1.9
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39357.json"