Description
deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.
Remediation
References
https://fluidattacks.com/advisories/heldens/
https://github.com/mattphillips/deep-object-diff
Related Vulnerabilities
CVE-2020-7758 Vulnerability in npm package browserless-chrome
CVE-2018-1002204 Vulnerability in npm package adm-zip
CVE-2023-40787 Vulnerability in maven package org.springblade:blade-core-tool
CVE-2017-16163 Vulnerability in npm package dylmomo
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-shuffle_2.10