Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16487

Опубликовано: 01 фев. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 5.6

Описание

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

4.17.11+dfsg-4
disco

not-affected

4.17.11+dfsg-2
eoan

not-affected

4.17.11+dfsg-4
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

not-affected

4.17.11+dfsg-4
esm-apps/jammy

not-affected

4.17.11+dfsg-4
esm-apps/noble

not-affected

4.17.11+dfsg-4

Показывать по

EPSS

Процентиль: 73%
0.01553
Низкий

6.8 Medium

CVSS2

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
почти 8 лет назад

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

CVSS3: 5.6
nvd
больше 7 лет назад

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

CVSS3: 5.6
debian
больше 7 лет назад

A prototype pollution vulnerability was found in lodash <4.17.11 where ...

github
больше 7 лет назад

Prototype Pollution in lodash

CVSS3: 5.6
fstec
почти 8 лет назад

Уязвимость функций merge, mergeWith и defaultsDeep библиотеки Lodash, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 73%
0.01553
Низкий

6.8 Medium

CVSS2

5.6 Medium

CVSS3