Description
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-PROPERTYEXPR-598800
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598857
https://github.com/jquense/expr/commit/df846910915d59f711ce63c1f817815bceab5ff7
Related Vulnerabilities
CVE-2021-4260 Vulnerability in npm package oils
CVE-2022-24794 Vulnerability in npm package express-openid-connect
CVE-2023-37944 Vulnerability in maven package org.datadog.jenkins.plugins:datadog
CVE-2021-21342 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-21290 Vulnerability in maven package io.netty:netty-common