Description
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick, set, setWith, update, updateWith, and zipObjectDeep allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.10.2
References
Could your website be exposed too?
SmartScanner can check your website for Prototype Pollution in lodash - lodash.update and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Prototype Pollution in lodash - lodash - GHSA-p6mc-m468-83gw - CVE-2020-8203
- Prototype Pollution in lodash - lodash-es - CVE-2020-8203
- Prototype Pollution in lodash - lodash.set - CVE-2020-8203
- Prototype Pollution in lodash - lodash.updatewith - CVE-2020-8203


