A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lodash | Lodash | * | 4.17.11 (excluding) |
Node-lodash | Ubuntu | bionic | * |
Node-lodash | Ubuntu | cosmic | * |
Node-lodash | Ubuntu | esm-apps/bionic | * |
Node-lodash | Ubuntu | esm-apps/xenial | * |
Node-lodash | Ubuntu | upstream | * |
Node-lodash | Ubuntu | xenial | * |