HIGH7.3
GHSA-7wpw-2hjm-89gp
Prototype Pollution in merge
Quick fix
GHSA-7wpw-2hjm-89gp — merge: upgrade to the fixed version with the command below.
npm install merge@2.1.1Details
All versions of package merge <2.1.1 are vulnerable to Prototype Pollution via _recursiveMerge .
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-28499[ADVISORY]
- https://github.com/yeikos/js.merge/commit/7b0ddc2701d813f2ba289b32d6a4b9d4cc235fb4[WEB]
- https://github.com/yeikos/js.merge/blob/56ca75b2dd0f2820f1e08a49f62f04bbfb8c5f8f/src/index.ts#L64[WEB]
- https://github.com/yeikos/js.merge/blob/master/src/index.ts#L64[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1071049[WEB]
- https://snyk.io/vuln/SNYK-JS-MERGE-1042987[WEB]
- https://vuldb.com/?id.170146[WEB]