Description
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Remediation
References
https://snyk.io/vuln/SNYK-JS-MOOTOOLS-1325536
Related Vulnerabilities
CVE-2021-3629 Vulnerability in maven package io.undertow:undertow-core
CVE-2021-20190 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-13343 Vulnerability in maven package com.butor:portal
CVE-2023-44487 Vulnerability in maven package io.helidon.http:helidon-http-http2