lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., proto) can be copied during a merge or clone operation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mquery | Mquery_project | * | 3.2.3 (excluding) |
Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | RedHat | rhacm2/acm-must-gather-rhel8:v2.1.6-6 | * |