Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
Related Vulnerabilities
CVE-2020-9482 Vulnerability in maven package org.apache.nifi.registry:nifi-registry-web-api
CVE-2023-25653 Vulnerability in npm package node-jose
CVE-2022-24718 Vulnerability in npm package @finastra/ssr-pages
CVE-2019-3875 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2021-21428 Vulnerability in maven package org.openapitools:openapi-generator-online