QID 377843

Date Published: 2022-12-20

QID 377843: Lodash Prototype Pollution Vulnerability

Lodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.

Affected Version
lodash prior to 4.17.20

QID Detection Logic
It checks for the vulnerable version of lodash using npm list command

An attacker can exploit the system via Prototype Pollution.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to update to the patched version of lodash modules lodash v4.17.20
    Vendor References

    CVEs related to QID 377843

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-8203 URL Logo nvd.nist.gov/vuln/detail/CVE-2020-8203