
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-992f-wf4w-x36v) is a Prototype Pollution issue affecting all versions of the merge-objects npm package. This security flaw was published to the GitHub Advisory Database on September 1, 2020, and was last updated on January 9, 2023. The vulnerability affects all versions of the package (>= 0.0.0) with no patched versions available (GitHub Advisory).
The vulnerability is classified as CWE-1321 and has been assessed with a Low severity rating. The issue specifically relates to Prototype Pollution in the merge-objects npm package, which could potentially allow attackers to manipulate object prototypes (GitHub Advisory).
The vulnerability affects the security of applications using the merge-objects npm package, potentially allowing attackers to exploit Prototype Pollution vulnerabilities. This could lead to property injection or modification of JavaScript object prototypes (GitHub Advisory).
While specific exploit details are not publicly disclosed, the vulnerability has been confirmed to affect all versions of the merge-objects package. The low severity rating suggests limited exploitation potential (GitHub Advisory).
No direct fix is available for this vulnerability. The official recommendation is to use an alternative package instead of merge-objects, as no patched versions have been released (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."