Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
Related Vulnerabilities
CVE-2022-36033 Vulnerability in maven package org.jsoup:jsoup
CVE-2021-23624 Vulnerability in npm package dotty
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-elastic-udfs-parent
CVE-2023-49804 Vulnerability in npm package uptime-kuma
CVE-2021-32691 Vulnerability in npm package data-connector-rock