Description
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Remediation
References
https://github.com/doowb/expand-hash/blob/556913f6c2f05848110b5b8261cfc78e5ce3dc77/index.js#L19
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25948
Related Vulnerabilities
CVE-2020-7630 Vulnerability in npm package git-add-remote
CVE-2018-3734 Vulnerability in npm package stattic
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:github-com-faisalman-ua-parser-js
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.12
CVE-2021-21350 Vulnerability in maven package com.thoughtworks.xstream:xstream