GHSA-c6h4-gc3f-hgjq
Dashboard / Vulnerabilities / GHSA-c6h4-gc3f-hgjq
Summary: Prototype Pollution in js-data
Details: All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
References: https://nvd.nist.gov/vuln/detail/CVE-2021-23574, https://github.com/js-data/js-data/issues/576, https://github.com/js-data/js-data/issues/577, https://github.com/js-data/js-data, https://github.com/js-data/js-data/blob/master/dist/js-data.js%23L472, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2320790, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2320791, https://snyk.io/vuln/SNYK-JS-JSDATA-1584361
Affected packages
Package
Name: js-data
Purl: pkg:npm/js-data
Affected ranges
Type: SEMVER
Events:
