Description
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/380878
Related Vulnerabilities
CVE-2022-0087 Vulnerability in npm package @keystone-6/auth
CVE-2022-24441 Vulnerability in npm package snyk
CVE-2022-31180 Vulnerability in npm package shescape
CVE-2010-1870 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint