Description
The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.
Remediation
References
https://github.com/gulpjs/copy-props/pull/7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1088047
https://snyk.io/vuln/SNYK-JS-COPYPROPS-1082870
Related Vulnerabilities
CVE-2013-7370 Vulnerability in npm package connect
CVE-2021-4329 Vulnerability in npm package json-logic-js
CVE-2018-14721 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2018-1270 Vulnerability in maven package org.springframework:spring-messaging