Description
undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://github.com/remy/undefsafe/commit/f272681b3a50e2c4cbb6a8533795e1453382c822
https://snyk.io/vuln/SNYK-JS-UNDEFSAFE-548940
Related Vulnerabilities
CVE-2018-20676 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2021-39157 Vulnerability in npm package detect-character-encoding
CVE-2012-3546 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2018-18893 Vulnerability in maven package com.hubspot.jinjava:jinjava