HIGH7.3
GHSA-5xjx-4xcm-hpcm
Prototype Pollution in ts-nodash
Quick fix
GHSA-5xjx-4xcm-hpcm — ts-nodash: upgrade to the fixed version with the command below.
npm install ts-nodash@1.2.7Details
`ts-nodash` before version 1.2.7 is vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23403[ADVISORY]
- https://github.com/BadOPCode/NoDash/commit/b9cc2b3b49f6cd5228e406bc57e17a28b998fea5[WEB]
- https://github.com/BadOPCode/NoDash[PACKAGE]
- https://github.com/BadOPCode/NoDash/blob/master/src/Merge.ts[WEB]
- https://snyk.io/vuln/SNYK-JS-TSNODASH-1311009[WEB]