Description
A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.1
References
Could your website be exposed too?
SmartScanner can check your website for @ndhoule/defaults prototype pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- deep-defaults vulnerable to prototype pollution - CVE-2021-25944
- @intlify/shared Prototype Pollution vulnerability - CVE-2024-52810
- vxe-table prototype pollution - CVE-2024-57080
- @intlify/shared Prototype Pollution vulnerability - vue-i18n - CVE-2024-52810
You might also like:
See something that needs correcting? Let us knowUpdated February 06, 2025


