CVE-2018-3721
PoC —CVSS 3.1
6.5 medium
EPSS
2%p83
Published
()
Modified
Description
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
In the news0 stories
No ingested article mentions this CVE yet.