Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2022-22968 Vulnerability in maven package org.springframework:spring-context
CVE-2023-34613 Vulnerability in maven package net.sf.sojo:sojo
CVE-2022-4493 Vulnerability in maven package io.scif:scifio
CVE-2019-17558 Vulnerability in maven package org.apache.solr:solr-velocity
CVE-2015-8860 Vulnerability in maven package org.webjars.npm:tar