Description
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
Remediation
References
https://hackerone.com/reports/430291
Related Vulnerabilities
CVE-2022-4375 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-32685 Vulnerability in npm package tenvoy
CVE-2022-29252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2021-21160 Vulnerability in npm package electron
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-common