Description
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/380878
Related Vulnerabilities
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs
CVE-2020-36048 Vulnerability in maven package org.webjars.npm:engine.io
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2023-46495 Vulnerability in npm package @evershop/evershop
CVE-2017-20162 Vulnerability in maven package org.webjars.npm:ms