Description
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.
Remediation
References
https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/main.js#L2194
https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/main.js#L647
https://github.com/stealjs/steal/issues/1533
Related Vulnerabilities
CVE-2016-10640 Vulnerability in npm package node-thulac
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-el
CVE-2019-10752 Vulnerability in npm package sequelize
CVE-2019-17495 Vulnerability in maven package io.springfox:springfox-swagger-ui
CVE-2020-11987 Vulnerability in maven package org.apache.xmlgraphics:batik-svgbrowser