CVE-2022-24802

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:deepmerge-ts_project:deepmerge-ts:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-04-01 00:15

Updated : 2022-04-11 18:38


NVD link : CVE-2022-24802

Mitre link : CVE-2022-24802

CVE.ORG link : CVE-2022-24802


JSON object : View

Products Affected

deepmerge-ts_project

  • deepmerge-ts
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes