Description
This affects all versions of package mout. The deepFillIn function can be used to ‘fill missing properties recursively’, while the deepMixIn ‘mixes objects into the target object, recursively mixing existing child objects as well’. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
Recommendation
Update the mout package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.3
- Patched version(s): 1.2.3
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in mout - mout and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype pollution in json-pointer - json-pointer - CVE-2020-7709
- Prototype Pollution in lodash - lodash-es - CVE-2020-8203
- Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gw - CVE-2020-8203
- Prototype Pollution in decal - decal - CVE-2020-28449


