Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2021-28164 Vulnerability in maven package org.eclipse.jetty:jetty-webapp
CVE-2020-7656 Vulnerability in maven package org.fujion.webjars:jquery
CVE-2023-45278 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2023-40827 Vulnerability in maven package org.pf4j:pf4j
CVE-2022-2900 Vulnerability in maven package org.webjars.npm:parse-url