CVE-2018-16472: Improper Input Validation
(updated )
A prototype pollution attack in cached-path-relative allows an attacker to inject properties on Object.prototype
which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
References
Detect and mitigate CVE-2018-16472 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →