Description
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://github.com/mikaelkaron/grunt-util-property/blob/master/main.js%23L41
https://security.snyk.io/vuln/SNYK-JS-GRUNTUTILPROPERTY-565088
Related Vulnerabilities
CVE-2017-5635 Vulnerability in maven package org.apache.nifi:nifi-web-security
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-namesrv
CVE-2020-7679 Vulnerability in maven package org.webjars.bower:casperjs
CVE-2017-16108 Vulnerability in npm package gaoxiaotingtingting
CVE-2021-21320 Vulnerability in npm package matrix-react-sdk