Input validation error in Lodash - CVE-2018-3721

 

Input validation error in Lodash - CVE-2018-3721

Published: June 7, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37072
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3721
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to manipulate data.

lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.


Affected software

Lodash
QRadar Pulse App
IBM Watson Machine Learning Accelerator
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
MobileFirst Platform
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Pak for Business Automation
IBM Process Mining
IBM Security Verify Governance

How to mitigate CVE-2018-3721

Install update from vendor's website.

Lodash - update to 4.17.5
QRadar Pulse App - update to 2.2.9
IBM Watson Machine Learning Accelerator - update to 2.3.4
DevOps Test Performance - update to 11.0.8
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Process Mining - update to 1.12.0.4
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins