Description
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MERGEDEEP2-1727593
Related Vulnerabilities
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2017-16021 Vulnerability in npm package uri-js
CVE-2021-32828 Vulnerability in maven package org.nuxeo.ecm.platform:nuxeo-platform-oauth
CVE-2022-24762 Vulnerability in npm package sysend
CVE-2019-6286 Vulnerability in maven package org.webjars.npm:node-sass