CRITICAL9.1
GHSA-jf85-cpcp-j695
Prototype Pollution in lodash
Quick fix
GHSA-jf85-cpcp-j695 — lodash: upgrade to the fixed version with the command below.
npm install lodash@4.17.12Details
Versions of `lodash` before 4.17.12 are vulnerable to Prototype Pollution. The function `defaultsDeep` allows a malicious user to modify the prototype of `Object` via `{constructor: {prototype: {...}}}` causing the addition or modification of an existing property that will exist on all objects.
## Recommendation
Update to version 4.17.12 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10744[ADVISORY]
- https://github.com/lodash/lodash/pull/4336[WEB]
- https://access.redhat.com/errata/RHSA-2019:3024[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-10744.yml[WEB]
- https://security.netapp.com/advisory/ntap-20191004-0005[WEB]
- https://snyk.io/vuln/SNYK-JS-LODASH-450202[WEB]
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSS[WEB]
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&utm_medium=RSS[WEB]
- https://www.oracle.com/security-alerts/cpujan2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2020.html[WEB]