Description
All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.
Remediation
References
https://github.com/metabench/jsgui-lang-essentials/issues/1
https://snyk.io/vuln/SNYK-JS-JSGUILANGESSENTIALS-2316897
Related Vulnerabilities
CVE-2022-27200 Vulnerability in maven package io.jenkins.plugins:folder-auth
CVE-2023-33246 Vulnerability in maven package org.apache.rocketmq:rocketmq-broker
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2022-39236 Vulnerability in npm package matrix-js-sdk
CVE-2022-36899 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations