QID 982607
QID 982607: Nodejs (npm) Security Update for json8-merge-patch (GHSA-8v9x-9xqg-r8mr)
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8v9x-9xqg-r8mr for updates pertaining to this vulnerability.
Vendor References
- GHSA-8v9x-9xqg-r8mr -
github.com/advisories/GHSA-8v9x-9xqg-r8mr
CVEs related to QID 982607
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8v9x-9xqg-r8mr | json8-merge-patch |
|