Description
Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.
Recommendation
Update the @75lb/deep-merge package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.1.1
- Patched version(s): 1.1.2
References
Related Issues
- njwt Prototype Pollution vulnerability - CVE-2024-34273
- vue-i18n has cross-site scripting vulnerability with prototype pollution (GHSA-9r9m-ffp6-9x4v) 2 - CVE-2024-52809
- vue-i18n has cross-site scripting vulnerability with prototype pollution (GHSA-9r9m-ffp6-9x4v) 3 - CVE-2024-52809
- node-opcua-alarm-condition prototype pollution vulnerability - CVE-2024-57086
- Tags:
- npm
- @75lb/deep-merge
Anything's wrong? Let us know Last updated on August 06, 2024