Prototype Pollution Vulnerability in Lodash by Lodash
CVE-2018-16487

5.6MEDIUM

Key Information:

Vendor

Hackerone

Status
Vendor
CVE Published:
1 February 2019

What is CVE-2018-16487?

A prototype pollution vulnerability exists in Lodash versions prior to 4.17.11, allowing attackers to exploit the merge, mergeWith, and defaultsDeep functions. This exploit can lead to unauthorized modifications of properties within Object.prototype, potentially resulting in significant application security risks. Proper mitigation strategies must be implemented to protect against this vulnerability.

Affected Version(s)

lodash <4.7.11

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.