QID 377843
Date Published: 2022-12-20
QID 377843: Lodash Prototype Pollution Vulnerability
Lodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.
Affected Version
lodash prior to 4.17.20
QID Detection Logic
It checks for the vulnerable version of lodash using npm list command
An attacker can exploit the system via Prototype Pollution.
Solution
Customers are advised to update to the patched version of lodash modules lodash v4.17.20
Vendor References
- GHSA-p6mc-m468-83gw -
github.com/advisories/GHSA-p6mc-m468-83gw
CVEs related to QID 377843
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-8203 |
|