Description
Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Remediation
References
https://github.com/rumkin/keyget/commit/17d15b6c75036eb429075a8cfeccfc18094dd2e2
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28272
Related Vulnerabilities
CVE-2022-31160 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2022-31142 Vulnerability in npm package fastify-bearer-auth
CVE-2022-31051 Vulnerability in npm package semantic-release
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2022-41965 Vulnerability in maven package org.opencastproject:opencast-engage-paella-player