Description
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Remediation
References
https://cwe.mitre.org/data/definitions/1321.html
https://github.com/Tencent/vConsole/issues/616
Related Vulnerabilities
CVE-2017-16135 Vulnerability in npm package serverzyy
CVE-2021-46708 Vulnerability in npm package swagger-ui
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2021-31411 Vulnerability in maven package com.vaadin:flow-server