CVE-2021-39227

Improperly Controlled Modification of Dynamically-Determined Object Attributes in npm/zrender

Identifier

CVE-2021-39227

Package Slug

npm/zrender

Vulnerability

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Description

ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. Using merge and clone helper methods in the src/core/util.ts module results in prototype pollution.

Affected Versions

All versions before 5.2.1

Solution

Upgrade to version 5.2.1 or above.

Last Modified

2021-10-01

source