Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25079
HistoryApr 28, 2020 - 9:42 a.m.

Prototype Pollution

2020-04-2809:42:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.017 Low

EPSS

Percentile

87.7%

lodash is vulnerable to prototype pollution attack. The vulnerability exists due to the ability to inject properties on Object.prototype using the function zipObjectDeep, leading to DoS, and possibly other forms of attacks.