Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2021-23421 Vulnerability in npm package merge-change
CVE-2021-3757 Vulnerability in npm package immer
CVE-2021-40822 Vulnerability in maven package org.geoserver:gs-main
CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation
CVE-2023-47321 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web