Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mjjj-6p43-vhhv: Prototype Pollution in deep-get-set

All versions of package deep-get-set are vulnerable to Prototype Pollution via the ‘deep’ function. Note: This vulnerability derives from an incomplete fix of CVE-2020-7715

ghsa
#vulnerability#js#git

Prototype Pollution in deep-get-set

High severity GitHub Reviewed Published Jun 25, 2022 • Updated Jun 29, 2022

Related news

CVE-2022-21231: Prototype Pollution in deep-get-set | CVE-2022-21231 | Snyk

All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)