Description
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
Remediation
References
https://runkit.com/embed/sq8qjwemyn8t
https://snyk.io/vuln/SNYK-JS-XASSIGN-1759314
Related Vulnerabilities
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard-impl
CVE-2020-28267 Vulnerability in npm package @strikeentco/set
CVE-2019-14517 Vulnerability in npm package editor.md
CVE-2021-4264 Vulnerability in maven package org.webjars:dustjs-linkedin