GHSA-fhjf-83wg-r2j9
Dashboard / Vulnerabilities / GHSA-fhjf-83wg-r2j9
GHSA-fhjf-83wg-r2j9
Summary: Prototype Pollution in mixin-deep
Details: Versions of `mixin-deep` prior to 2.0.1 or 1.3.2 are vulnerable to Prototype Pollution. The `mixinDeep` function fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects. ## Recommendation If you are using `mixin-deep` 2.x, upgrade to version 2.0.1 or later. If you are using `mixin-deep` 1.x, upgrade to version 1.3.2 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10746, https://github.com/jonschlinkert/mixin-deep/commit/8f464c8ce9761a8c9c2b3457eaeee9d404fa7af9, https://github.com/jonschlinkert/mixin-deep/commit/90ee1fab375fccfd9b926df718243339b4976d50, https://lists.fedoraproject.org/archives/list/[email protected]/message/BFNIVG2XYFPZJY3DYYBJASZ7ZMKBMIJT, https://lists.fedoraproject.org/archives/list/[email protected]/message/UXRA365KZCUNXMU3KDH5JN5BEPNIGUKC, https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212, https://www.npmjs.com/advisories/1013, https://www.oracle.com//security-alerts/cpujul2021.html
Affected packages
Package
Name: mixin-deep
Purl: pkg:npm/mixin-deep
Affected ranges
Type: SEMVER
Events:
