Description
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Remediation
References
https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211
https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803
Related Vulnerabilities
CVE-2022-45389 Vulnerability in maven package com.cloudbees.jenkins.plugins:xpdev
CVE-2021-23381 Vulnerability in npm package killing
CVE-2021-32854 Vulnerability in maven package org.webjars:textangular
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker
CVE-2020-14967 Vulnerability in maven package org.webjars.bower:jsrsasign