nested-object-assign@1.0.3 vulnerabilities
Package to support nested merging of objects & properties, using Object.Assign
-
latest version
1.0.4
-
latest non vulnerable version
-
first published
7 years ago
-
latest version published
3 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the nested-object-assign package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
nested-object-assign is a Package to support nested merging of objects & properties, using Object.Assign Affected versions of this package are vulnerable to Prototype Pollution via the default function, as demonstrated by running the PoC below. PoC
How to fix Prototype Pollution? Upgrade |
<1.0.4
|