Description
The package nested-object-assign before 1.0.4 are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below.
Remediation
References
https://github.com/Geta/NestedObjectAssign/pull/11
https://snyk.io/vuln/SNYK-JS-NESTEDOBJECTASSIGN-1065977
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-36184 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-45133 Vulnerability in npm package @babel/traverse
CVE-2021-39150 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-31070 Vulnerability in npm package @ffdc/nestjs-proxy