Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Remediation
References
https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4
Related Vulnerabilities
CVE-2021-22147 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2019-8331 Vulnerability in maven package org.fujion.webjars:bootstrap
CVE-2018-14627 Vulnerability in maven package org.wildfly:wildfly-feature-pack
CVE-2008-6504 Vulnerability in maven package org.apache.struts:struts2-core