Description
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/381185
Related Vulnerabilities
CVE-2018-3744 Vulnerability in npm package html-pages
CVE-2021-3918 Vulnerability in npm package json-schema
CVE-2022-24948 Vulnerability in maven package org.apache.jspwiki:jspwiki-main
CVE-2023-50709 Vulnerability in npm package @cubejs-backend/api-gateway
CVE-2016-4437 Vulnerability in maven package org.apache.shiro:shiro-core