Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.
The issue permits deletion of properties but does not allow overwriting their original behavior.
This issue is patched on 4.17.23
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lodash | Lodash | 4.0.0 (including) | 4.17.23 (excluding) |
| Cryostat 4 on RHEL 9 | RedHat | cryostat/cryostat-openshift-console-plugin-rhel9:4.1.0-17 | * |
| Cryostat 4 on RHEL 9 | RedHat | cryostat/cryostat-rhel9:4.1.0-17 | * |
| Red Hat Enterprise Linux 10 | RedHat | pcs-0:0.12.1-1.el10_1.2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | pcs-0:0.12.0-3.el10_0.4 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | pcs-0:0.10.8-1.el8_4.10 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | pcs-0:0.10.8-1.el8_4.10 | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | pcs-0:0.10.12-6.el8_6.12 | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | pcs-0:0.10.12-6.el8_6.12 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | pcs-0:0.10.15-4.el8_8.10 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | pcs-0:0.10.15-4.el8_8.10 | * |
| Red Hat Enterprise Linux 9 | RedHat | pcs-0:0.11.10-1.el9_7.2 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | pcs-0:0.11.1-10.el9_0.10 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | pcs-0:0.11.4-7.el9_2.7 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | pcs-0:0.11.7-2.el9_4.6 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | pcs-0:0.11.9-2.el9_6.3 | * |
| Network Observability (NETOBSERV) 1.11.0 | RedHat | network-observability/network-observability-console-plugin-compat-rhel9:sha256:325db5ee476d5467e24748b6a66def44ff06e91e7e0665f43a49d7df9dbc9870 | * |
| Network Observability (NETOBSERV) 1.11.0 | RedHat | network-observability/network-observability-console-plugin-rhel9:sha256:3f4b1539a41af46e0dcc3ee1e06d760b504448190cf1f5963171e504cbcb82e2 | * |
| Red Hat Developer Hub 1.8 | RedHat | rhdh/rhdh-hub-rhel9:sha256:114b288483eccad70b18159c9f75de9c061bdf9ee269198a75c3efeb68a43a2b | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:sha256:2ff9787699ff67dab7ee6f300d84651233f499aac8aeee10bfe21381806393c4 | * |
| Red Hat OpenShift Container Platform 4.14 | RedHat | openshift4/ose-console:sha256:39af4cee0a425da0814b28bdd6d515a397544d3c5f83b5e9cfffb7aa33c4fbb5 | * |
| Red Hat OpenShift Container Platform 4.16 | RedHat | openshift4/ose-console-rhel9:sha256:2996e3821813cad87e4bbef83d22bab2bdb80ade147e2f827714321a06d50769 | * |
| Red Hat OpenShift Container Platform 4.17 | RedHat | openshift4/ose-console-rhel9:sha256:80793968484982ba2d52eabd86548f294b096923a432049a73b39cf51e31b889 | * |
| Red Hat OpenShift Container Platform 4.18 | RedHat | openshift4/ose-console-rhel9:sha256:6a7462a57f3b25a5fc080fbe5daa50e2a5ee09b80b1f3015abc184ee079fd550 | * |
| Red Hat OpenShift Container Platform 4.19 | RedHat | openshift4/ose-console-rhel9:sha256:f4a65b5386d74b203f29b8fbff069211fc756bdade1ecbdaffdb64a289bad2a7 | * |
| Red Hat OpenShift Container Platform 4.2 | RedHat | openshift4/ose-console-rhel9:sha256:422f8d8700c8be8f4a532894a4c62fb1a4affbd29b8772097a5e790bb528656e | * |
| Red Hat OpenShift Container Platform 4.21 | RedHat | openshift4/ose-monitoring-plugin-rhel9:sha256:b0f7fd94fa47603540b7c49967aa1921d5c1c063576f6ecee524a52400bd1089 | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-ossmc-rhel8:sha256:4e910b08863756516707f2ad8198c04dc6d706c78f481561a3b2e896800d4dbe | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-rhel8:sha256:ad1449f9047107c23d5b0e53c3ca148a12a9729dd7aa474c5eadb55870f314fa | * |
| Red Hat OpenShift Service Mesh 3 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:19c44dfb277123122abafc25552fe408ea7ad6dc026aa592f53e3a754ca0a44f | * |
| Red Hat OpenShift Service Mesh 3 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:527fd434b3b1f9b9304adbedd89a593ca347a84571a68c7935afe6aa207db49f | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:e5a71ca768b96c827dd2fd860cbd739d7743f1eeb89b2e4c7cc9157941683626 | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:a60d01bfe3bfa2dc484f9d940b71538f0b3732cb77db883edb7a93cf42f2992e | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:fcb5d2c8e4ae372cb0009dc15d46eb5a10163139b61b063115c3d3fce90265e1 | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:ef18675f445508d01ae56ef59709b70d4b69187bb03425061cac62998f643fe5 | * |
| Red Hat Trusted Artifact Signer 1.2 | RedHat | rhtas/rekor-search-ui-rhel9:sha256:1e3a46ade52215e2c78df9229f36301c94099e8397ee74ab99fb8bd504ce7aa2 | * |
| Red Hat Trusted Artifact Signer 1.3 | RedHat | rhtas/rhtas-console-ui-rhel9:sha256:e7ee88dd498d337304db3d90f4f352e55114475dbc9d75c3b18a49a249492b1e | * |