Description
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.0.1
References
Related Issues
- qs vulnerable to Prototype Pollution - CVE-2022-24999
- thlorenz browserify-shim vulnerable to prototype pollution (GHSA-r737-347m-wqc7) - CVE-2022-37621
- Parse Server vulnerable to Prototype Pollution via Cloud Code Webhooks or Cloud Code Triggers - CVE-2022-41878
- Parse Server is vulnerable to Prototype Pollution via Cloud Code Webhooks - CVE-2022-41879
- Tags:
- npm
- grunt-karma
Anything's wrong? Let us know Last updated on October 19, 2023