Description
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEEPLY-451026
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.bower:layui
CVE-2021-46384 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-40351 Vulnerability in maven package org.jenkins-ci.plugins:favorite-view
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was