Description
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Remediation
References
https://hackerone.com/reports/980649
Related Vulnerabilities
CVE-2021-44550 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2021-24033 Vulnerability in npm package react-dev-utils
CVE-2022-45391 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2022-29172 Vulnerability in maven package org.webjars.npm:auth0-lock