Description
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MERGEDEEP2-1727593
Related Vulnerabilities
CVE-2021-21423 Vulnerability in npm package projen
CVE-2020-28495 Vulnerability in npm package total.js
CVE-2011-4969 Vulnerability in maven package org.webjars.bower:jquery
CVE-2021-21306 Vulnerability in maven package org.webjars.npm:marked
CVE-2022-41881 Vulnerability in maven package io.netty:netty-codec-haproxy