Lucene search

K
osvGoogleOSV:CVE-2018-3721
HistoryJun 07, 2018 - 2:29 a.m.

CVE-2018-3721

2018-06-0702:29:08
Google
osv.dev
5

0.001 Low

EPSS

Percentile

46.8%

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of “Object” via proto, causing the addition or modification of an existing property that will exist on all objects.