Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3829-mgmw-jcg4: Prototype Pollution in deep.assign

deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes (‘Prototype Pollution’).

ghsa
#nodejs#git#perl

Prototype Pollution in deep.assign

Moderate severity GitHub Reviewed Published Jul 1, 2022 • Updated Jul 6, 2022

Related news

CVE-2021-40663: Prototype Pollution in deep.assign npm package · Issue #1 · janbialostok/deep-assign

deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').