Description
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).
Recommendation
Update the immer package to the latest compatible version. Followings are version details:
- Affected version(s): >= 7.0.0, < 9.0.6
- Patched version(s): 9.0.6
References
Related Issues
- Prototype Pollution in immer - CVE-2021-23436
- Prototype Pollution in dojo - CVE-2021-23450
- Prototype Pollution in handlebars - handlebars - CVE-2021-23383
- npm package rfc6902 vulnerable to Prototype Pollution - CVE-2021-4245
You might also like:
- Tags:
- npm
- immer
Anything's wrong? Let us know Last updated on April 25, 2024


