Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Remediation
References
https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4
Related Vulnerabilities
CVE-2011-2092 Vulnerability in maven package com.adobe.blazeds:blazeds-common
CVE-2022-29244 Vulnerability in maven package org.webjars.npm:npm
CVE-2022-26112 Vulnerability in maven package org.apache.pinot:pinot-spi
CVE-2018-11786 Vulnerability in maven package org.apache.karaf.shell:org.apache.karaf.shell.core
CVE-2014-3596 Vulnerability in maven package org.apache.axis:axis