CVE-2022-39357
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.14%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1321
- CWE-1321
Referencias
- https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1
- https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f
- https://github.com/wintercms/winter/releases/tag/v1.1.10
- https://github.com/wintercms/winter/releases/tag/v1.2.1
- https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q
- https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1
- https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f
- https://github.com/wintercms/winter/releases/tag/v1.1.10
- https://github.com/wintercms/winter/releases/tag/v1.2.1
- https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-39357",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-39357",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-23T15:47:25.512688Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "wintercms",
"product": "winter",
"versions": [
{
"status": "affected",
"version": ">= 1.1.8, < 1.1.10"
},
{
"status": "affected",
"version": "= 1.2.0"
}
]
}
]
}
],
"published": "2022-10-26T15:15:20.250",
"references": [
{
"url": "https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/wintercms/winter/releases/tag/v1.1.10",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/wintercms/winter/releases/tag/v1.2.1",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/wintercms/winter/releases/tag/v1.1.10",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/wintercms/winter/releases/tag/v1.2.1",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-1321"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1321"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts."
},
{
"lang": "es",
"value": "Winter es un sistema de administración de contenidos gratuito y de código abierto basado en el framework PHP Laravel. El framework Snowboard en versiones 1.1.8, 1.1.9 y 1.2.0, es vulnerable a una contaminación de prototipos en la clase principal de Snowboard así como en su cargador de plugins. La rama 1.0 de Winter no está afectada, ya que no contiene el framework Snowboard. Este problema ha sido parcheado en versiones 1.1.10 y 1.2.1. Como mitigación, puede evitarse este problema siguiendo algunas prácticas comunes de seguridad para JavaScript, incluyendo la implementación de una política de seguridad de contenidos y la auditoría de scripts"
}
],
"lastModified": "2026-06-17T04:58:12.517",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wintercms:winter:1.1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25F4ACF9-EC8A-4364-B2BA-85E84249BC6D"
},
{
"criteria": "cpe:2.3:a:wintercms:winter:1.1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76A06D2A-A8E4-4806-8CE0-B0D80F1AC67C"
},
{
"criteria": "cpe:2.3:a:wintercms:winter:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DB89CAA-64A8-45A4-8A78-F1C79908C96B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}