Description
All current versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.8.1
References
Related Issues
- @ianwalter/merge Prototype Pollution via `merge` function - CVE-2021-23397
- Prototype Pollution in the merge and clone helper methods - CVE-2021-39227
- merge vulnerable to Prototype Pollution - CVE-2021-3645
- json-schema is vulnerable to Prototype Pollution - CVE-2021-3918
You might also like:
- Tags:
- npm
- merge-change
Anything's wrong? Let us know Last updated on February 01, 2023


