Description
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
Remediation
References
https://hackerone.com/reports/430291
Related Vulnerabilities
CVE-2022-31147 Vulnerability in npm package jquery-validation
CVE-2023-45133 Vulnerability in maven package org.webjars.npm:babel-traverse
CVE-2023-46659 Vulnerability in maven package org.jenkins-ci.plugins:trac
CVE-2020-7598 Vulnerability in maven package org.webjars.npm:minimist
CVE-2022-42466 Vulnerability in maven package org.apache.isis.viewer:isis-viewer-wicket-ui