CVE-2019-10744
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Affected (81)
Products: Lodash: Lodash · Netapp: Active Iq Unified Manager, Service Level Manager · Redhat: Virtualization Manager · +2 more
Show all products
Lodash: Lodash · Netapp: Active Iq Unified Manager, Service Level Manager · Redhat: Virtualization Manager · Oracle: Banking Extensibility Workbench · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Application Visibility And Reporting, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator, Big Iq Centralized Management, Iworkflow
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.3 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.3.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 12.1.0 to 12.1.5.2 | |
| From 6.0.0 to 6.1.0 | |
| Version 2.3.0 |
References (12)
Source: report@snyk.io
Third Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.