Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2019-5416 Vulnerability in npm package localhost-now
CVE-2023-30465 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2020-28360 Vulnerability in npm package private-ip
CVE-2020-8127 Vulnerability in maven package org.webjars.bower:reveal.js