Back

MEDIUM

lodash: Prototype pollution in utilities function

Published Jun 7, 2018

Description

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms version 4.7 does not ship component lodash, so isn't affected by this flaw. Red Hat Virtualization 4.2 EUS includes a vulnerable version of lodash as part of the ovirt-engine-dashboard package. This package has been removed from Red Hat Virtualization 4.3.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jun 7, 2018
Updated Sep 16, 2024
Reserved Dec 28, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 15, 2018
GHSA-FVQR-27WR-82FM