Description
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.0.1
References
Related Issues
- thlorenz browserify-shim vulnerable to prototype pollution (GHSA-cfgr-75jx-h88g) - CVE-2022-37623
- steal vulnerable to Prototype Pollution - CVE-2022-37258
- thlorenz browserify-shim vulnerable to prototype pollution (GHSA-r737-347m-wqc7) - CVE-2022-37621
- thlorenz browserify-shim vulnerable to prototype pollution - CVE-2022-37617
- Tags:
- npm
- grunt-karma
Anything's wrong? Let us know Last updated on October 19, 2023