All the vulnerabilities related to the version 0.1.8 of the package
Prototype Pollution in defaults-deep
All versions of defaults-deep
are vulnerable to prototype pollution. Provided certain input defaults-deep
can add or modify properties of the Object
prototype. These properties will be present on all objects.
As no patch is currently available for this vulnerability it is our recommendation to select another module that can provide this functionality.
Prototype Pollution Vulnerability in parse-git-config
An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function.