Description
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
Remediation
References
https://github.com/MrSwitch/hello.js/issues/634
Related Vulnerabilities
CVE-2022-40149 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2019-14862 Vulnerability in maven package org.jszip.redist:knockout
CVE-2022-42003 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-33546 Vulnerability in maven package org.codehaus.janino:janino-parent
CVE-2023-44270 Vulnerability in maven package org.webjars.npm:postcss