Description
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-PROTO-1316301
https://www.npmjs.com/package/Proto
Related Vulnerabilities
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2021-46365 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2020-26217 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-25645 Vulnerability in npm package dset
CVE-2023-45134 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates