Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvqr-27wr-82fm

Опубликовано: 26 июл. 2018
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Prototype Pollution in lodash

Versions of lodash before 4.17.5 are vulnerable to prototype pollution.

The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of Object via __proto__ causing the addition or modification of an existing property that will exist on all objects.

Recommendation

Update to version 4.17.5 or later.

Пакеты

Наименование

lodash

npm
Затронутые версииВерсия исправления

< 4.17.5

4.17.5

Наименование

lodash-rails

rubygems
Затронутые версииВерсия исправления

< 4.17.5

4.17.5

EPSS

Процентиль: 44%
0.00215
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321
CWE-471

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 2.9
redhat
почти 8 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 6.5
nvd
больше 7 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 6.5
debian
больше 7 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assume ...

EPSS

Процентиль: 44%
0.00215
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-1321
CWE-471