Description
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Remediation
References
https://hackerone.com/reports/869574
Related Vulnerabilities
CVE-2020-35211 Vulnerability in maven package io.atomix:atomix
CVE-2023-45857 Vulnerability in npm package axios
CVE-2021-20218 Vulnerability in maven package io.fabric8:kubernetes-client
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2020-36632 Vulnerability in maven package org.webjars.npm:flat