Description
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Remediation
References
https://hackerone.com/reports/869574
Related Vulnerabilities
CVE-2022-25921 Vulnerability in npm package morgan-json
CVE-2021-39152 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-28472 Vulnerability in npm package aws-sdk
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-type-builder
CVE-2023-40348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook