Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
Related Vulnerabilities
CVE-2022-0639 Vulnerability in npm package url-parse
CVE-2021-43308 Vulnerability in npm package markdown-link-extractor
CVE-2018-19360 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2012-0818 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxb-provider
CVE-2022-31139 Vulnerability in maven package io.github.karlatemp:unsafe-accessor