Vulnerabilities/

Collection.js vulnerable to Prototype Pollution

Severity:
High

Description

Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.

Recommendation

Update the collection.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
collection.js
Anything's wrong? Let us know Last updated on November 29, 2023

This issue is available in SmartScanner Professional

See Pricing