Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2019-0192 Vulnerability in maven package org.apache.solr:solr-core
CVE-2019-17556 Vulnerability in maven package org.apache.olingo:odata-client-proxy
CVE-2022-27202 Vulnerability in maven package org.jenkins-ci.plugins:extended-choice-parameter
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-manager
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14