CVE-2022-24802

8.1HIGH

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecord

发布于: 4/1/2022更新于: 11/21/2024

描述

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.

AI分析AI驱动

受影响产品

deepmerge-ts_projectdeepmerge-ts

参考资料