Description
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/380878
Related Vulnerabilities
CVE-2022-21724 Vulnerability in maven package org.postgresql:postgresql
CVE-2022-36095 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-45282 Vulnerability in npm package openmct
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2022-0198 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp