Description
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-TINYCONF-598792
Related Vulnerabilities
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-hadoop-dbcp-service
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-core
CVE-2020-28496 Vulnerability in npm package three
CVE-2022-31190 Vulnerability in maven package org.dspace:dspace-xmlui
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests