Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2020-7672 Vulnerability in npm package mosc
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2021-41117 Vulnerability in npm package keypair
CVE-2008-6504 Vulnerability in maven package opensymphony:xwork
CVE-2023-24998 Vulnerability in maven package org.apache.tomcat:tomcat-util