A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.
2019-02-01T18:29:00.943
2024-11-21T03:52:51.170
Modified
CVSSv3.1: 5.6 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4