Description
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://github.com/mikaelkaron/grunt-util-property/blob/master/main.js%23L41
https://security.snyk.io/vuln/SNYK-JS-GRUNTUTILPROPERTY-565088
Related Vulnerabilities
CVE-2018-8319 Vulnerability in npm package msrcrypto
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2018-11771 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2020-7684 Vulnerability in npm package rollup-plugin-serve-favicon