Description
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-PROTO-1316301
https://www.npmjs.com/package/Proto
Related Vulnerabilities
CVE-2020-8175 Vulnerability in npm package jpeg-js
CVE-2020-7753 Vulnerability in npm package trim
CVE-2020-7710 Vulnerability in npm package safe-eval
CVE-2020-8908 Vulnerability in maven package com.google.guava:guava
CVE-2011-4367 Vulnerability in maven package org.apache.myfaces.core:myfaces-impl