Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Remediation
References
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C
Related Vulnerabilities
CVE-2023-34612 Vulnerability in maven package com.helger.commons:ph-json
CVE-2020-19697 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2022-25893 Vulnerability in npm package vm2
CVE-2021-46708 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2018-8815 Vulnerability in maven package org.opencms:opencms-core