Lack of data validation In deep-extend
Description
Prototype Pollution in deep-extend
Versions of deep-extend before 0.5.1 are vulnerable to prototype pollution.
Recommendation
Update to version 0.5.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 0.5.1 | ||
debian 11 | 0.4.1-2 | ||
debian 14 | 0.4.1-2 | ||
debian 12 | 0.4.1-2 | ||
debian 13 | 0.4.1-2 | ||
rpm rhel8 | 1:12.20.1-1.module+el8.3.0+9503+19cb079c | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.