Description
Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.
Remediation
References
https://github.com/MrSwitch/hello.js/issues/634
Related Vulnerabilities
CVE-2013-4366 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2023-30331 Vulnerability in maven package com.ibeetl:beetl
CVE-2023-24163 Vulnerability in maven package cn.hutool:hutool-all
CVE-2022-0084 Vulnerability in maven package org.jboss.xnio:xnio-api
CVE-2019-10184 Vulnerability in maven package io.undertow:undertow-servlet