Description
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Remediation
References
Related Vulnerabilities
WordPress 3.9.1 Multiple Vulnerabilities (3.9 - 3.9.1)
Joomla! Core 3.9.x Cross-Site Scripting (3.9.0 - 3.9.20)
WordPress Plugin Hitasoft FLV Player 'id' Parameter SQL Injection (1.1)
WordPress 2.5 Cookie Integrity Protection Unauthorized Access Vulnerability (0.6.2 - 2.5)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3412)