QID 984083
QID 984083: Nodejs (npm) Security Update for assign-deep (GHSA-xcvv-84j5-jw9h)
Versions of `assign-deep` before 0.4.7 are vulnerable to prototype pollution via merging functions. ## Recommendation Update to version 0.4.7 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xcvv-84j5-jw9h for updates pertaining to this vulnerability.
Vendor References
- GHSA-xcvv-84j5-jw9h -
github.com/advisories/GHSA-xcvv-84j5-jw9h
CVEs related to QID 984083
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xcvv-84j5-jw9h | assign-deep |
|