Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
Related Vulnerabilities
CVE-2018-11786 Vulnerability in maven package org.apache.karaf.shell:org.apache.karaf.shell.core
CVE-2020-21176 Vulnerability in npm package thinkjs
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-managesieve
CVE-2021-21294 Vulnerability in maven package org.http4s:http4s-blaze-server_2.12