Description
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.
Remediation
References
https://hackerone.com/reports/801522
Related Vulnerabilities
CVE-2022-40149 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2020-7743 Vulnerability in maven package org.webjars.npm:mathjs
CVE-2020-28478 Vulnerability in npm package gsap
CVE-2021-43821 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl
CVE-2023-40809 Vulnerability in maven package org.opencrx:opencrx-core-models