Security Advisory

CVE-2019-10744

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-25 23:43:03
Last updated 2024-08-04 22:32:01
Assigner snyk
CVSS score not scored
State PUBLISHED

Description

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.