This site is an independent open-source project and is not affiliated with, endorsed by, or sponsored by npm, Inc. or GitHub, Inc. The name “npm” is a registered trademark of npm, Inc., used here solely to describe compatibility and reference publicly available npm package data.
Version Details and Security Vulnerabilities
📦
nested-object-assign
1.0.2
Comparision Betweeen 1.0.2 and 1.0.1
Identify the differences between the current version of the package and the previous one.
Version
Dependencies
0
0
Dev Dependencies
24
0
Peer Dependencies
24
0
Distributed Files
N/A
N/A
Unpacked Size
N/A
N/A
Security Vulnerabilities
Security Details
Comprehensive list of direct or transitive vulnerabilities for version 1.0.2 of the package nested-object-assign.
All Security Vulnerabilities
All the vulnerabilities related to the version 1.0.2 of the package
Summary:
Prototype pollution in nested-object-assign
Details:
The package nested-object-assign before 1.0.4 is vulnerable to Prototype Pollution via the default function.