Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Remediation
References
https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4
Related Vulnerabilities
CVE-2017-16008 Vulnerability in npm package i18next
CVE-2015-9241 Vulnerability in npm package hapi
CVE-2011-1475 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-43417 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2011-2526 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core