Description
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-COMPONENTFLATTEN-548907
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2022-36918 Vulnerability in maven package org.jenkins-ci.plugins:buckminster
CVE-2021-29481 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2019-15488 Vulnerability in maven package org.igniterealtime.openfire:xmppserver