Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Remediation
References
https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4
Related Vulnerabilities
CVE-2020-7647 Vulnerability in maven package org.jooby:jooby
CVE-2022-37734 Vulnerability in maven package com.graphql-java:graphql-java
CVE-2022-25167 Vulnerability in maven package org.apache.flume:flume-parent
CVE-2022-36944 Vulnerability in maven package org.scala-lang:scala-library
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:arquillian-tomee-common