Description
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
Remediation
References
https://hackerone.com/reports/430291
Related Vulnerabilities
CVE-2014-4671 Vulnerability in npm package hapi
CVE-2020-25689 Vulnerability in maven package org.wildfly.core:wildfly-protocol
CVE-2012-0392 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2017-16008 Vulnerability in maven package org.webjars.bower:i18next
CVE-2020-14966 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign