CVE-2018-3721

All FrameworksLodashCWE-471CVE-2018-3721

CVE-2018-3721

State: PUBLISHED · Published: 2018-06-07 · Updated: 2024-09-16 · Assigner: hackerone
Description
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2018/3xxx/CVE-2018-3721.json