mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
| Software | From | Fixed in |
|---|---|---|
| mixin-deep_project / mixin-deep | - | 1.3.2 |
| mixin-deep_project / mixin-deep | 2.0.0 | 2.0.0.x |
| fedoraproject / fedora | 30 | 30.x |
| fedoraproject / fedora | 31 | 31.x |
| oracle / communications_cloud_native_core_network_function_cloud_native_environment | 1.4.0 | 1.4.0.x |
jonschlinkert / mixin-deep
|
- | 1.3.2 |
jonschlinkert / mixin-deep
|
2.0.0 | 2.0.0.x |
jonschlinkert / mixin-deep
|
2.0.0 | 2.0.1 |