Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
Related Vulnerabilities
CVE-2023-28709 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2018-20698 Vulnerability in maven package com.floragunn:search-guard-kibana-plugin
CVE-2023-46494 Vulnerability in npm package @evershop/evershop
CVE-2020-28469 Vulnerability in maven package org.webjars.npm:glob-parent
CVE-2023-35145 Vulnerability in maven package org.jenkins-ci.plugins:sonargraph-integration