GHSA-fhv8-fx5f-7fxf
Dashboard / Vulnerabilities / GHSA-fhv8-fx5f-7fxf
Summary: Prototype Pollution in the merge and clone helper methods
Details: ### Impact Using `merge` and `clone` helper methods in the `src/core/util.ts` module will have prototype pollution. It will affect the popular data visualization library Apache ECharts, which is using and exported these two methods directly. ### Patches It has been patched in https://github.com/ecomfe/zrender/pull/826. Users should update zrender to `5.2.1`. and update echarts to `5.2.1` if project is using echarts. ### References NA ### For more information NA
References: https://github.com/ecomfe/zrender/security/advisories/GHSA-fhv8-fx5f-7fxf, https://nvd.nist.gov/vuln/detail/CVE-2021-39227, https://github.com/ecomfe/zrender/pull/826, https://github.com/ecomfe/zrender, https://github.com/ecomfe/zrender/releases/tag/5.2.1
Affected packages
Package
Name: zrender
Purl: pkg:npm/zrender
Affected ranges
Type: SEMVER
Events:
