nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
Published Jul 25, 2019
9.1
CRITICALCVSS 3.1
EPSS 5.01%
Description
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Affected products
-
- Version All versions prior to 4.17.12StatusaffectedConstraints-
- Version
Configuration 2
- n/a
- n/a
- n/a
- n/a
Configuration 3
- 4.3
Configuration 4
- 14.3.0
- 14.4.0
Configuration 5
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · ≤ 12.1.5
- ≥ 13.1.0 · ≤ 13.1.3
- ≥ 14.1.0 · ≤ 14.1.2
- ≥ 15.0.0 · < 15.0.1.3
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · ≤ 13.1.3
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.1.0 · < 15.1.1
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 12.1.0 · < 12.1.5.2
- ≥ 13.1.0 · < 13.1.3.4
- ≥ 14.1.0 · < 14.1.2.5
- ≥ 15.0.0 · < 15.0.1.4
- ≥ 15.1.0 · < 15.1.0.2
- ≥ 6.0.0 · ≤ 6.1.0
- 5.4.0
- 7.0.0
- 2.3.0
No data.
Jaeger-1.17
distributed-tracing/jaeger-all-in-one-rhel7:1.17.2-3
Fixed · RHSA-2020:2819
Jaeger-1.17
distributed-tracing/jaeger-query-rhel7:1.17.2-3
Fixed · RHSA-2020:2819
OpenShift Service Mesh 1.0
servicemesh-grafana-0:6.2.2-36.el8
Fixed · RHSA-2020:2362
Openshift Service Mesh 1.0
jaeger-0:v1.13.1.redhat7-1.el7
Fixed · RHSA-2020:2362
Openshift Service Mesh 1.0
kiali-0:v1.0.11.redhat1-1.el7
Fixed · RHSA-2020:2362
Red Hat AMQ 7.10.0
nodejs-lodash
Fixed · RHSA-2022:5101
Red Hat Fuse 7.10
nodejs-lodash
Fixed · RHSA-2021:5134
Red Hat Virtualization Engine 4.3
ovirt-web-ui-0:1.6.0-1.el7ev
Fixed · RHSA-2019:3024
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Red Hat OpenShift Container Platform 3.10
nodejs-lodash
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-kibana5
Will not fix
Red Hat OpenShift Container Platform 3.9
nodejs-lodash
Fix deferred
Red Hat OpenShift Container Platform 4
logging-kibana5-container
Will not fix
Red Hat Quay 3
quay/quay-rhel8
Will not fix
Red Hat Software Collections
rh-nodejs10-nodejs
Not affected
Red Hat Software Collections
rh-nodejs8-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Jaeger-1.17 | distributed-tracing/jaeger-all-in-one-rhel7:1.17.2-3 | Fixed | RHSA-2020:2819 |
| Jaeger-1.17 | distributed-tracing/jaeger-query-rhel7:1.17.2-3 | Fixed | RHSA-2020:2819 |
| OpenShift Service Mesh 1.0 | servicemesh-grafana-0:6.2.2-36.el8 | Fixed | RHSA-2020:2362 |
| Openshift Service Mesh 1.0 | jaeger-0:v1.13.1.redhat7-1.el7 | Fixed | RHSA-2020:2362 |
| Openshift Service Mesh 1.0 | kiali-0:v1.0.11.redhat1-1.el7 | Fixed | RHSA-2020:2362 |
| Red Hat AMQ 7.10.0 | nodejs-lodash | Fixed | RHSA-2022:5101 |
| Red Hat Fuse 7.10 | nodejs-lodash | Fixed | RHSA-2021:5134 |
| Red Hat Virtualization Engine 4.3 | ovirt-web-ui-0:1.6.0-1.el7ev | Fixed | RHSA-2019:3024 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | nodejs-lodash | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-kibana5 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | nodejs-lodash | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | logging-kibana5-container | Will not fix | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs | Not affected | n/a |
lodash-rails
RubyGems
Introduced 0 Fixed 4.17.12lodash
npm
Introduced 0 Fixed 4.17.12lodash-es
npm
Introduced 0 Fixed 4.17.14lodash-amd
npm
Introduced 0 Fixed 4.17.13lodash.defaultsdeep
npm
Introduced 0 Fixed 4.6.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| RubyGems | lodash-rails | 0 | 4.17.12 |
| npm | lodash | 0 | 4.17.12 |
| npm | lodash-es | 0 | 4.17.14 |
| npm | lodash-amd | 0 | 4.17.13 |
| npm | lodash.defaultsdeep | 0 | 4.6.1 |
Remediation
Red Hat statement
The lodash dependency is included in OpenShift Container Platform (OCP) by Kibana in the aggregated logging stack. Elastic have issued a security advisory (ESA-2019-10) for Kibana for this vulnerability, and in that advisory stated that no exploit vectors had been identified in Kibana. Therefore we rate this issue as moderate for OCP and may fix this issue in a future release. https://www.elastic.co/community/security This issue did not affect the versions of rh-nodejs8-nodejs and rh-nodejs10-nodejs as shipped with Red Hat Software Collections. Whilst a vulnerable version of lodash has been included in ServiceMesh, the impact is lowered to Moderate due to the library not being directly accessible increasing the attack complexity and the fact that the attacker would need some existing access - meaning the vulnerability is not crossing a privilege boundary. Red Hat Quay imports lodash as a runtime dependency of restangular. The restangular function in use by Red Hat Quay do not use lodash to parse user input. This issue therefore rated moderate impact for Red Hat Quay.
References (15)
- https://access.redhat.com/errata/RHSA-2019:3024 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-10744 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1739497 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0597 Advisory
- https://github.com/advisories/GHSA-jf85-cpcp-j695 Advisory
- https://github.com/lodash/lodash/pull/4336
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-10744.yml
- https://nvd.nist.gov/vuln/detail/CVE-2019-10744
- https://security.netapp.com/advisory/ntap-20191004-0005 x_refsource_CONFIRMThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-LODASH-450202 x_refsource_CONFIRMExploitThird Party Advisory
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&utm_medium=RSS
- https://www.cve.org/CVERecord?id=CVE-2019-10744
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.