Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2019-10435 Vulnerability in maven package org.jenkins-ci.plugins:vault-scm-plugin
CVE-2020-7730 Vulnerability in npm package bestzip
CVE-2022-23541 Vulnerability in npm package jsonwebtoken
CVE-2019-1010091 Vulnerability in maven package org.webjars.bower:tinymce
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common