Skip to content

object-deep-assign Prototype Pollution

Moderate severity GitHub Reviewed Published Jun 17, 2024 to the GitHub Advisory Database • Updated Jun 17, 2024

Package

npm @alexbinary/object-deep-assign (npm)

Affected versions

<= 1.0.11

Patched versions

None

Description

alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)

References

Published by the National Vulnerability Database Jun 17, 2024
Published to the GitHub Advisory Database Jun 17, 2024
Reviewed Jun 17, 2024
Last updated Jun 17, 2024

Severity

Moderate

Weaknesses

No CWEs

CVE ID

CVE-2024-36582

GHSA ID

GHSA-4xg3-7w7q-856q
Checking history
See something to contribute? Suggest improvements for this vulnerability.