Description
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://github.com/mikaelkaron/grunt-util-property/blob/master/main.js%23L41
https://security.snyk.io/vuln/SNYK-JS-GRUNTUTILPROPERTY-565088
Related Vulnerabilities
CVE-2017-2604 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-16177 Vulnerability in npm package chatbyvista
CVE-2019-1003065 Vulnerability in maven package org.jenkins-ci.plugins:cloudshare-docker
CVE-2020-9484 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2016-7103 Vulnerability in maven package org.webjars:jquery-ui