Description
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
Remediation
References
https://hackerone.com/reports/430291
Related Vulnerabilities
CVE-2021-23463 Vulnerability in maven package com.h2database:h2
CVE-2021-41165 Vulnerability in npm package ckeditor4
CVE-2017-16183 Vulnerability in npm package iter-server
CVE-2022-24823 Vulnerability in maven package io.netty:netty-codec-http
CVE-2020-36640 Vulnerability in maven package org.bonitasoft.connectors:bonita-connector-webservice