Description
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Remediation
References
https://cwe.mitre.org/data/definitions/1321.html
https://github.com/Tencent/vConsole/issues/616
Related Vulnerabilities
CVE-2021-46704 Vulnerability in npm package genieacs
CVE-2021-23568 Vulnerability in npm package extend2
CVE-2021-23356 Vulnerability in npm package kill-process-by-name
CVE-2023-44483 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3