Description
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/380878
Related Vulnerabilities
CVE-2019-20174 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2021-43787 Vulnerability in npm package nodebb
CVE-2022-0084 Vulnerability in maven package org.jboss.xnio:xnio-api
CVE-2021-39133 Vulnerability in maven package org.rundeck:rundeck
CVE-2021-41973 Vulnerability in maven package org.apache.mina:mina-http