Description
Prototype pollution vulnerability in ‘deep-defaults’ versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.0.0, <= 1.0.5
References
Related Issues
- deep-object-diff vulnerable to Prototype Pollution - CVE-2022-41713
- Prototype Pollution in deep-override - CVE-2021-25941
- mootools-more vulnerable to prototype pollution - CVE-2021-20088
- jszip Vulnerable to Prototype Pollution - CVE-2021-23413
You might also like:
- Tags:
- npm
- deep-defaults
Anything's wrong? Let us know Last updated on April 22, 2024


