This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2022-02-04T20:05:12.083691Z
Updated: 2024-09-16T23:32:07.792Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23470
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-02-04T20:15:08.363
Modified: 2022-02-09T02:07:00.743
Link: CVE-2021-23470
Redhat
No data.