Description
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
Remediation
References
https://github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10b
https://github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2
https://security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975
Related Vulnerabilities
CVE-2022-25916 Vulnerability in npm package mt7688-wiscan
CVE-2022-4942 Vulnerability in npm package eslint-detailed-reporter
CVE-2020-6427 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-23412 Vulnerability in npm package gitlogplus
CVE-2022-21803 Vulnerability in maven package org.webjars.npm:nconf