GHSA-pjxw-22xf-6pwc
Dashboard / Vulnerabilities / GHSA-pjxw-22xf-6pwc
Summary: Prototype Pollution in defaults-deep
Details: All versions of `defaults-deep` are vulnerable to prototype pollution. Provided certain input `defaults-deep` can add or modify properties of the `Object` prototype. These properties will be present on all objects. ## Recommendation As no patch is currently available for this vulnerability it is our recommendation to select another module that can provide this functionality.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-16486, https://hackerone.com/reports/380878, https://github.com/advisories/GHSA-pjxw-22xf-6pwc, https://github.com/jonschlinkert/defaults-deep, https://www.npmjs.com/advisories/778
Affected packages
Package
Name: defaults-deep
Purl: pkg:npm/defaults-deep
Affected ranges
Type: SEMVER
Events:
