Description
All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
Remediation
References
https://snyk.io/vuln/SNYK-JS-MERGEDEEP2-1727593
Related Vulnerabilities
CVE-2020-36180 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-39235 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation
CVE-2022-38545 Vulnerability in npm package valine
CVE-2012-0393 Vulnerability in maven package org.apache.struts:struts2-core