Description
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MERGEDEEP2-1727593
Related Vulnerabilities
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2020-13942 Vulnerability in maven package org.apache.unomi:unomi-services
CVE-2011-4905 Vulnerability in maven package activemq:activemq-core
CVE-2022-25890 Vulnerability in npm package wifey
CVE-2022-24785 Vulnerability in maven package org.webjars.npm:moment