Description
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEEPLY-451026
Related Vulnerabilities
CVE-2021-3137 Vulnerability in maven package org.xwiki.commons:xwiki-commons
CVE-2022-36896 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2022-22880 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2021-31597 Vulnerability in npm package xmlhttprequest-ssl
CVE-2022-34113 Vulnerability in maven package io.dataease:dataease-plugin-common