Description
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Remediation
References
https://hackerone.com/reports/980649
Related Vulnerabilities
CVE-2021-28860 Vulnerability in npm package mixme
CVE-2015-0250 Vulnerability in maven package org.eclipse.birt.runtime.3_7_1:org.apache.batik.dom
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.validation
CVE-2020-12648 Vulnerability in maven package org.webjars.npm:tinymce