Description
deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.
Remediation
References
https://fluidattacks.com/advisories/buuren/
https://github.com/sibu-github/deep-parse-json
Related Vulnerabilities
CVE-2021-29452 Vulnerability in npm package a12n-server
CVE-2021-21234 Vulnerability in maven package eu.hinsch:spring-boot-actuator-logview
CVE-2021-41183 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2023-29211 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2022-43422 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-utilities