Back

HIGH

nodejs-lodash: prototype pollution in zipObjectDeep function

Published Jul 15, 2020

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Affected products

Remediation

Red Hat statement

In OpenShift ServiceMesh (OSSM), Red Hat OpenShift Jaeger (RHOSJ) and Red Hat OpenShift Container Platform (RHOCP), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-lodash library is used, but due to the code changing to the container first content the kibana package is marked as wontfix. This may be fixed in the future. Red Hat Virtualization uses vulnerable version of nodejs-lodash, however zipObjectDeep is not used, therefore the impact is low.

Metrics

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jul 15, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 27, 2020
GHSA-P6MC-M468-83GW