Description
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.
Remediation
References
https://github.com/jarradseers/config-handler/issues/1
https://snyk.io/vuln/SNYK-JS-CONFIGHANDLER-1564947
Related Vulnerabilities
CVE-2016-7103 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2021-23417 Vulnerability in npm package deepmergefn
CVE-2020-36649 Vulnerability in maven package org.webjars.npm:papaparse
CVE-2020-19698 Vulnerability in maven package org.webjars.bower:editor.md
CVE-2021-21294 Vulnerability in maven package org.http4s:http4s-blaze-server_2.12