Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2018-20843 Vulnerability in npm package dbus
CVE-2024-4367 Vulnerability in maven package org.webjars.npm:pdfjs-dist
CVE-2019-10371 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth
CVE-2022-43424 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2018-1000613 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on