Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-24802: Build software better, together

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.

CVE
#nodejs#java

Prototype Pollution in deepmerge-ts

Package

npm deepmerge-ts (npm)

Description

deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords().

CVE ID

CVE-2022-24802

GHSA ID

GHSA-r9w3-g83q-m6hq

CWEs

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907