Description
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
Remediation
References
https://github.com/timdown/rangy/issues/478
https://security.snyk.io/vuln/SNYK-JS-RANGY-3175702
Related Vulnerabilities
CVE-2021-43138 Vulnerability in maven package org.webjars.bowergithub.caolan:async
CVE-2018-16487 Vulnerability in npm package @sailshq/lodash
CVE-2021-44906 Vulnerability in maven package org.webjars.bowergithub.substack:minimist
CVE-2023-42268 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2022-24823 Vulnerability in maven package io.netty:netty-codec-http