CVE-2019-10744
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 5.0%
exploitation probability
5.0%top 8% of all CVEs
observed exploitation
nono source reports it
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Affected products
Snyk · lodashReferences
https://access.redhat.com/errata/RHSA-2019:3024https://security.netapp.com/advisory/ntap-20191004-0005/https://snyk.io/vuln/SNYK-JS-LODASH-450202https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSShttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html