Description
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MERGEDEEP2-1727593
Related Vulnerabilities
CVE-2022-22963 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-core
CVE-2022-25901 Vulnerability in npm package cookiejar
CVE-2017-11556 Vulnerability in npm package node-sass
CVE-2023-43642 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2016-9177 Vulnerability in maven package com.sparkjava:spark-core