Description
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
Remediation
References
https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/babel.js#L4216
https://github.com/stealjs/steal/blob/c9dd1eb19ed3f97aeb93cf9dcea5d68ad5d0ced9/ext/babel.js#L4569
https://github.com/stealjs/steal/issues/1534
Related Vulnerabilities
CVE-2021-23383 Vulnerability in maven package org.webjars.npm:handlebars
CVE-2014-3607 Vulnerability in maven package org.ldaptive:ldaptive
CVE-2023-32314 Vulnerability in npm package vm2
CVE-2022-25979 Vulnerability in npm package jsuites
CVE-2019-12741 Vulnerability in maven package ca.uhn.hapi.fhir:hapi-fhir-testpage-overlay