QID 981899
QID 981899: Nodejs (npm) Security Update for controlled-merge (GHSA-5pg7-v24c-9rp9)
Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5pg7-v24c-9rp9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-5pg7-v24c-9rp9 -
github.com/advisories/GHSA-5pg7-v24c-9rp9
CVEs related to QID 981899
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5pg7-v24c-9rp9 | controlled-merge |
|