This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-02-04T20:05:12.083691Z

Updated: 2024-09-16T23:32:07.792Z

Reserved: 2021-01-08T00:00:00

Link: CVE-2021-23470

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-04T20:15:08.363

Modified: 2022-02-09T02:07:00.743

Link: CVE-2021-23470

cve-icon Redhat

No data.