Description
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
Remediation
References
https://hackerone.com/reports/430291
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars.npm:codemirror
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was
CVE-2021-21252 Vulnerability in npm package jquery-validation
CVE-2021-25924 Vulnerability in maven package cd.go.plugin:go-plugin-api
CVE-2021-37695 Vulnerability in maven package org.webjars.npm:ckeditor4