Back

CRITICAL

nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties

Published Jul 25, 2019

Description

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Affected products

Remediation

Red Hat statement

The lodash dependency is included in OpenShift Container Platform (OCP) by Kibana in the aggregated logging stack. Elastic have issued a security advisory (ESA-2019-10) for Kibana for this vulnerability, and in that advisory stated that no exploit vectors had been identified in Kibana. Therefore we rate this issue as moderate for OCP and may fix this issue in a future release. https://www.elastic.co/community/security This issue did not affect the versions of rh-nodejs8-nodejs and rh-nodejs10-nodejs as shipped with Red Hat Software Collections. Whilst a vulnerable version of lodash has been included in ServiceMesh, the impact is lowered to Moderate due to the library not being directly accessible increasing the attack complexity and the fact that the attacker would need some existing access - meaning the vulnerability is not crossing a privilege boundary. Red Hat Quay imports lodash as a runtime dependency of restangular. The restangular function in use by Red Hat Quay do not use lodash to parse user input. This issue therefore rated moderate impact for Red Hat Quay.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jul 25, 2019
Updated Aug 4, 2024
Reserved Apr 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 9, 2019
ENISA EUVD
Assigner snyk
Published Jul 25, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-0597 GHSA-JF85-CPCP-J695