HIGH7.3
GHSA-gjm5-83cw-p3p2
Prototype Pollution in extend2
Quick fix
GHSA-gjm5-83cw-p3p2 — extend2: upgrade to the fixed version with the command below.
npm install extend2@1.0.1Details
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23568[ADVISORY]
- https://github.com/eggjs/extend2/pull/2[WEB]
- https://github.com/eggjs/extend2/commit/aa332a59116c8398976434b57ea477c6823054f8[WEB]
- https://github.com/eggjs/extend2[PACKAGE]
- https://github.com/eggjs/extend2/blob/master/index.js%23L50-L60[WEB]
- https://snyk.io/vuln/SNYK-JS-EXTEND2-2320315[WEB]