Description
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
Remediation
References
https://github.com/MrSwitch/hello.js/issues/634
Related Vulnerabilities
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2018-5158 Vulnerability in maven package org.webjars.bower:pdfjs-dist
CVE-2023-44270 Vulnerability in maven package org.webjars.npm:postcss
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2020-28168 Vulnerability in maven package org.webjars.bower:axios