Description
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a8653b
https://snyk.io/vuln/SNYK-JS-BODYMEN-548897
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2022-25860 Vulnerability in maven package org.webjars.npm:simple-git
CVE-2020-8910 Vulnerability in maven package org.webjars.npm:google-closure-library
CVE-2022-36098 Vulnerability in maven package org.xwiki.platform:xwiki-platform-mentions-ui
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.codemirror:codemirror