Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Remediation
References
https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4
Related Vulnerabilities
CVE-2021-33611 Vulnerability in maven package org.webjars.bowergithub.vaadin:vaadin-menu-bar
CVE-2016-8750 Vulnerability in maven package org.apache.karaf.jaas:org.apache.karaf.jaas.modules
CVE-2023-38700 Vulnerability in npm package matrix-appservice-irc
CVE-2021-41189 Vulnerability in maven package org.dspace:dspace-api
CVE-2021-23353 Vulnerability in maven package org.webjars.bower:jspdf