Description
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/380878
Related Vulnerabilities
CVE-2022-23624 Vulnerability in npm package frourio-express
CVE-2022-23812 Vulnerability in npm package node-ipc
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_3
CVE-2023-5654 Vulnerability in npm package react-devtools
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:scandium