Skip to content

[vulnerability] All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge #40

@ekelvin

Description

@ekelvin

In absence of a security policy I am creating the issue here.
CVE-2020-28499
https://nvd.nist.gov/vuln/detail/CVE-2020-28499#match-6281551

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions