{"id":"GHSA-4xg3-7w7q-856q","summary":"object-deep-assign Prototype Pollution","details":"alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)","aliases":["CVE-2024-36582"],"modified":"2024-06-17T22:12:25.224813Z","published":"2024-06-17T15:30:54Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-17T21:37:37Z","nvd_published_at":"2024-06-17T15:15:51Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36582"},{"type":"WEB","url":"https://gist.github.com/mestrtee/9fe4d3a862c62ce6b2b0d20d4c5fd346"},{"type":"PACKAGE","url":"https://github.com/alexbinary/object-deep-assign"}],"affected":[{"package":{"name":"@alexbinary/object-deep-assign","ecosystem":"npm","purl":"pkg:npm/%40alexbinary/object-deep-assign"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.0.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-4xg3-7w7q-856q/GHSA-4xg3-7w7q-856q.json"}}],"schema_version":"1.9.0"}