Candidate: CVE-2018-16469 PublicDate: 2018-10-30 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16469 https://hackerone.com/reports/381194 https://www.npmjs.com/advisories/722 Description: The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a denial of service attack. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-merge: upstream_node-merge: released (1.2.1) precise/esm_node-merge: DNE trusty_node-merge: DNE trusty/esm_node-merge: DNE xenial_node-merge: ignored (end of standard support, was needed) bionic_node-merge: needed cosmic_node-merge: ignored (reached end-of-life) disco_node-merge: ignored (reached end-of-life) eoan_node-merge: ignored (reached end-of-life) focal_node-merge: needed groovy_node-merge: ignored (reached end-of-life) hirsute_node-merge: ignored (reached end-of-life) impish_node-merge: needed jammy_node-merge: needed devel_node-merge: needed