Prototype Pollution Vulnerability in Lodash by Lodash
CVE-2018-16487
5.6MEDIUM
What is CVE-2018-16487?
A prototype pollution vulnerability exists in Lodash versions prior to 4.17.11, allowing attackers to exploit the merge, mergeWith, and defaultsDeep functions. This exploit can lead to unauthorized modifications of properties within Object.prototype, potentially resulting in significant application security risks. Proper mitigation strategies must be implemented to protect against this vulnerability.
Affected Version(s)
lodash <4.7.11