-
Notifications
You must be signed in to change notification settings - Fork 3
Closed
Labels
securityNeeds immediate attentionNeeds immediate attentiontechnical debtIt was like this when I joined the projectIt was like this when I joined the project
Description
CVE-2019-10744
critical severity
Vulnerable versions: < 4.17.12
Patched version: 4.17.12
Affected versions of lodash are vulnerable to Prototype Pollution.
The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Metadata
Metadata
Assignees
Labels
securityNeeds immediate attentionNeeds immediate attentiontechnical debtIt was like this when I joined the projectIt was like this when I joined the project