Description
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
Remediation
References
https://github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10b
https://github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2
https://security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975
Related Vulnerabilities
CVE-2018-1999003 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-23615 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-39109 Vulnerability in npm package atlasboard
CVE-2017-9791 Vulnerability in maven package org.apache.struts:struts2-struts1-plugin
CVE-2022-0436 Vulnerability in maven package org.webjars.npm:grunt