Description
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Remediation
References
https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293
https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
Related Vulnerabilities
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2020-28469 Vulnerability in maven package org.webjars.bowergithub.es128:glob-parent
CVE-2021-32809 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega