Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-3721

Опубликовано: 07 июн. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*
Версия до 4.17.5 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:system_manager:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00215
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-471
CWE-1321

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 2.9
redhat
почти 8 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 6.5
debian
больше 7 лет назад

lodash node module before 4.17.5 suffers from a Modification of Assume ...

CVSS3: 6.5
github
больше 7 лет назад

Prototype Pollution in lodash

EPSS

Процентиль: 44%
0.00215
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-471
CWE-1321