QID 982963
QID 982963: Nodejs (npm) Security Update for nested-object-assign (GHSA-c497-v8pv-ch6x)
The package nested-object-assign before 1.0.4 is vulnerable to Prototype Pollution via the default function.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c497-v8pv-ch6x for updates pertaining to this vulnerability.
Vendor References
- GHSA-c497-v8pv-ch6x -
github.com/advisories/GHSA-c497-v8pv-ch6x
CVEs related to QID 982963
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c497-v8pv-ch6x | nested-object-assign |
|