QID 980908
QID 980908: Nodejs (npm) Security Update for defaults-deep (GHSA-pjxw-22xf-6pwc)
All versions of `defaults-deep` are vulnerable to prototype pollution. Provided certain input `defaults-deep` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
As no patch is currently available for this vulnerability it is our recommendation to select another module that can provide this functionality.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pjxw-22xf-6pwc for updates pertaining to this vulnerability.
Vendor References
- GHSA-pjxw-22xf-6pwc -
github.com/advisories/GHSA-pjxw-22xf-6pwc
CVEs related to QID 980908
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pjxw-22xf-6pwc | defaults-deep |
|