Lucene search

K
osvGoogleOSV:GHSA-JF85-CPCP-J695
HistoryJul 10, 2019 - 7:45 p.m.

Prototype Pollution in lodash

2019-07-1019:45:23
Google
osv.dev
30

EPSS

0.021

Percentile

89.2%

Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor: {prototype: {...}}} causing the addition or modification of an existing property that will exist on all objects.

Recommendation

Update to version 4.17.12 or later.