CRITICAL9.8
GHSA-fhjf-83wg-r2j9
Prototype Pollution in mixin-deep
Quick fix
GHSA-fhjf-83wg-r2j9 — mixin-deep: upgrade to the fixed version with the command below.
npm install mixin-deep@1.3.2Details
Versions of `mixin-deep` prior to 2.0.1 or 1.3.2 are vulnerable to Prototype Pollution. The `mixinDeep` function fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.
## Recommendation
If you are using `mixin-deep` 2.x, upgrade to version 2.0.1 or later. If you are using `mixin-deep` 1.x, upgrade to version 1.3.2 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10746[ADVISORY]
- https://github.com/jonschlinkert/mixin-deep/commit/8f464c8ce9761a8c9c2b3457eaeee9d404fa7af9[WEB]
- https://github.com/jonschlinkert/mixin-deep/commit/90ee1fab375fccfd9b926df718243339b4976d50[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFNIVG2XYFPZJY3DYYBJASZ7ZMKBMIJT[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXRA365KZCUNXMU3KDH5JN5BEPNIGUKC[WEB]
- https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212[WEB]
- https://www.npmjs.com/advisories/1013[WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]