Description
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied.
Recommendation
Update the lodash package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.7.0, < 4.17.19
- Patched version(s): 4.17.19
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gw and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in lodash - lodash-es - CVE-2020-8203
- Prototype Pollution in lodash - lodash.set - CVE-2020-8203
- Prototype Pollution in lodash - lodash.update - CVE-2020-8203
- Prototype Pollution in lodash - lodash.updatewith - CVE-2020-8203


