Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2020-36732 Vulnerability in maven package org.webjars.npm:crypto-js
CVE-2019-10323 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2021-21384 Vulnerability in npm package shescape
CVE-2021-32661 Vulnerability in npm package plugin-techdocs
CVE-2020-12265 Vulnerability in maven package org.webjars:decompress-tar