QID 982001
QID 982001: Nodejs (npm) Security Update for merge-deep (GHSA-r6rj-9ch6-g264)
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r6rj-9ch6-g264 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r6rj-9ch6-g264 -
github.com/advisories/GHSA-r6rj-9ch6-g264
CVEs related to QID 982001
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r6rj-9ch6-g264 | merge-deep |
|