Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2020-28865 Vulnerability in maven package com.github.kfcfans:powerjob
CVE-2023-26473 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2019-14862 Vulnerability in maven package org.webjars.npm:knockout
CVE-2020-11023 Vulnerability in maven package org.webjars.bower:jquery
CVE-2020-35149 Vulnerability in maven package org.webjars.npm:mquery