Description
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.0.1
References
Related Issues
- steal vulnerable to Prototype Pollution via optionName variable - CVE-2022-37264
- json-pointer vulnerable to Prototype Pollution - CVE-2022-4742
- deep-object-diff vulnerable to Prototype Pollution - CVE-2022-41713
- deep-parse-json vulnerable to Prototype Pollution - CVE-2022-42743
You might also like:
- Tags:
- npm
- grunt-karma
Anything's wrong? Let us know Last updated on October 19, 2023


