Description
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Remediation
References
https://hackerone.com/reports/980649
Related Vulnerabilities
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist
CVE-2023-36479 Vulnerability in maven package org.eclipse.jetty:jetty-servlets
CVE-2020-8244 Vulnerability in npm package bl
CVE-2022-23463 Vulnerability in maven package com.nepxion:discovery-commons
CVE-2020-5258 Vulnerability in maven package org.webjars.bowergithub.dojo:dojo