Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Remediation
References
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497
Related Vulnerabilities
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:sbt
CVE-2021-23543 Vulnerability in npm package realms-shim
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-34035 Vulnerability in maven package org.springframework.security:spring-security-config