Prototype Pollution In just-extend
Description
Prototype Pollution in just-extend
Versions of just-extend before 4.0.0 are vulnerable to prototype pollution. Provided certain input just-extend can add or modify properties of the Object prototype. These properties will be present on all objects.
Recommendation
Update to version 4.0.0 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 4.0.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.