Description
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
Remediation
References
https://github.com/automattic/mongoose/commit/305ce4ff789261df7e3f6e72363d0703e025f80d
https://huntr.dev/bounties/1eef5a72-f6ab-4f61-b31d-fc66f5b4b467
Related Vulnerabilities
CVE-2019-19919 Vulnerability in npm package handlebars
CVE-2011-1772 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2016-10006 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2020-1950 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes