Prototype Pollution In lodash-rails
Description
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 4.17.12 | ||
npm | 4.17.13 | ||
npm | 4.17.12 | ||
npm | 4.17.14 | ||
npm | 4.6.1 | ||
npm | 4.6.2 | ||
debian 11 | 4.17.15+dfsg-1 | ||
debian 13 | 4.17.15+dfsg-1 | ||
debian 14 | 4.17.15+dfsg-1 | ||
debian 12 | 4.17.15+dfsg-1 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.