Description
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
Remediation
References
https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-bbq.md
https://security.netapp.com/advisory/ntap-20241108-0002/
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.diguoyihao:layui
CVE-2013-2071 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-8215 Vulnerability in npm package canvas
CVE-2023-39410 Vulnerability in maven package org.apache.avro:avro
CVE-2021-37306 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base