๐ merge-deep Library up to 3.0.2 Prototype Object.prototype injection
๐ก Newskategorie: Sicherheitslรผcken
๐ Quelle: vuldb.com
A vulnerability was found in merge-deep Library up to 3.0.2 (Software Library). It has been classified as problematic. This affects the function Object.prototype
of the component Prototype Handler. Upgrading to version 3.0.3 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version. ...