Vulnerability identifier: #VU19305
Vulnerability risk: High
Exploitation vector: Network
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within the merge, mergeWith, and defaultsDeep functions. A remote attacker can send a specially crafted request and add or modify properties of Object.prototype.
Successful exploitation of this vulnerability may result in complete compromise of the affected application.
Install updates from vendor's website.
Vulnerable software versions
Lodash: 4.17.0 - 4.17.10
Fixed software versions
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?