Vulnerabilities/

Prototype Pollution in just-extend

Severity:
High

Description

Versions of just-extend before 4.0.0 are vulnerable to prototype pollution. Provided certain input just-extend can add or modify properties of the Object prototype. These properties will be present on all objects.

Recommendation

Update the just-extend package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
just-extend
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing