Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp
CVE-2020-7715 Vulnerability in npm package deep-get-set
CVE-2020-7752 Vulnerability in npm package systeminformation
CVE-2020-7678 Vulnerability in npm package node-import
CVE-2018-5673 Vulnerability in maven package org.webjars.bowergithub.dojo:dojo