CVE-2019-10744
published 2019-07-26CVE-2019-10744: Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
5.01%
91.3th percentile
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-lodash | < node-lodash 4.17.15+dfsg-1 (bookworm) | node-lodash 4.17.15+dfsg-1 (bookworm) |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5.2 | 12.1.5.2 |
| f5 | big-ip_access_policy_manager | >= 13.1.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_access_policy_manager | >= 15.0.0 < 15.0.1.4 | 15.0.1.4 |
| f5 | big-ip_access_policy_manager | >= 15.1.0 < 15.1.0.2 | 15.1.0.2 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5.2 | 12.1.5.2 |
| f5 | big-ip_advanced_firewall_manager | >= 13.1.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_advanced_firewall_manager | >= 15.0.0 < 15.0.1.4 | 15.0.1.4 |
| f5 | big-ip_advanced_firewall_manager | >= 15.1.0 < 15.1.0.2 | 15.1.0.2 |
| f5 | big-ip_analytics | 12.1.0 – 12.1.5 | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.3 | — |
| f5 | big-ip_analytics | 14.1.0 – 14.1.2 | — |
| f5 | big-ip_analytics | >= 15.0.0 < 15.0.1.3 | 15.0.1.3 |
| f5 | big-ip_analytics | >= 15.1.0 < 15.1.0.2 | 15.1.0.2 |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0 < 12.1.5.2 | 12.1.5.2 |
| f5 | big-ip_application_acceleration_manager | >= 13.1.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_application_acceleration_manager | >= 14.1.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_application_acceleration_manager | >= 15.0.0 < 15.0.1.4 | 15.0.1.4 |
| f5 | big-ip_application_acceleration_manager | >= 15.1.0 < 15.1.0.2 | 15.1.0.2 |
| f5 | big-ip_application_security_manager | >= 12.1.0 < 12.1.5.2 | 12.1.5.2 |
| f5 | big-ip_application_security_manager | >= 13.1.0 < 13.1.3.4 | 13.1.3.4 |
| f5 | big-ip_application_security_manager | >= 14.1.0 < 14.1.2.5 | 14.1.2.5 |
| f5 | big-ip_application_security_manager | >= 15.0.0 < 15.0.1.4 | 15.0.1.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_oracle9.8CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Core (Lodash) — CVE-2019-10744
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2019-10744 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Core (Lodash) — CVE-2019-10744
Oracle Oracle Financial Services Applications Risk Matrix: Core (Lodash) vulnerability
CVE: CVE-2019-10744
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
vendor_redhat·2019-08-09·CVSS 9.1
CVE-2019-10744 [CRITICAL] CWE-20 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
A Prototype Pollution vulnerability was found in lodash. Calling certain methods with untrusted JSON could lead to modifying objects up the prototype chain, including the global Object. A crafted JSON object passed to a vulnerable method could lead to denial of service or data injection, with various consequences.
Statement: The lodash dependency is included in OpenShift Container Platform (OCP) by Kibana in the aggregated logging stack. Elastic have issued a security advisory (ESA-2019-10) for
Red Hat
nodejs-set-value: prototype pollution in function set-value
vendor_redhat·2019-06-20·CVSS 9.1
CVE-2019-10747 [CRITICAL] CWE-471 nodejs-set-value: prototype pollution in function set-value
nodejs-set-value: prototype pollution in function set-value
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
A flaw was found in nodejs-set-value. The function mixin-deep can be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype, or _proto_ payloads. The highest threat from this vulnerability is to data confidentiality and integrity.
Statement: While OpenShift Container Platform (OCP) contains the affected nodejs-set-value code, it's added as a dependency of Kibana 5. Similar issue about prototype pollution [1] have been fixed, but no known attack vec
Debian
CVE-2019-10744: node-lodash - Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The...
vendor_debian·2019·CVSS 9.1
CVE-2019-10744 [CRITICAL] CVE-2019-10744: node-lodash - Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The...
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Scope: local
bookworm: resolved (fixed in 4.17.15+dfsg-1)
bullseye: resolved (fixed in 4.17.15+dfsg-1)
forky: resolved (fixed in 4.17.15+dfsg-1)
sid: resolved (fixed in 4.17.15+dfsg-1)
trixie: resolved (fixed in 4.17.15+dfsg-1)
OSV
CVE-2019-10744: Versions of lodash lower than 4
osv·2019-07-26·CVSS 9.1
CVE-2019-10744 [CRITICAL] CVE-2019-10744: Versions of lodash lower than 4
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
GHSA
Prototype Pollution in lodash
ghsa·2019-07-10
CVE-2019-10744 [CRITICAL] CWE-1321 Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of `lodash` before 4.17.12 are vulnerable to Prototype Pollution. The function `defaultsDeep` allows a malicious user to modify the prototype of `Object` via `{constructor: {prototype: {...}}}` causing the addition or modification of an existing property that will exist on all objects.
## Recommendation
Update to version 4.17.12 or later.
OSV
Prototype Pollution in lodash
osv·2019-07-10
CVE-2019-10744 [CRITICAL] Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of `lodash` before 4.17.12 are vulnerable to Prototype Pollution. The function `defaultsDeep` allows a malicious user to modify the prototype of `Object` via `{constructor: {prototype: {...}}}` causing the addition or modification of an existing property that will exist on all objects.
## Recommendation
Update to version 4.17.12 or later.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10746 nodejs-mixin-deep: prototype pollution in function mixin-deep
bugzilla·2020-01-28·CVSS 9.1
CVE-2019-10746 [CRITICAL] CVE-2019-10746 nodejs-mixin-deep: prototype pollution in function mixin-deep
CVE-2019-10746 nodejs-mixin-deep: prototype pollution in function mixin-deep
A vulnerability was found in Nodejs mixin-deep, where mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Reference:
https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212
Discussion:
Created nodejs-mixin-deep tracking bugs for this issue:
Affects: fedora-all [bug 1795476]
---
While OpenShift Container Platform (OCP) contains the affected nodejs-mixin-deep code, it's added as a dependency of Kibana 5. Similar issue about prototype pollution [1] have been fixed, but no known attack vector was found, so we're rating this issue as Low for OCP.
[1] CVE-201
Bugzilla
CVE-2019-10747 nodejs-set-value: prototype pollution in function set-value
bugzilla·2020-01-28·CVSS 9.1
CVE-2019-10747 [CRITICAL] CVE-2019-10747 nodejs-set-value: prototype pollution in function set-value
CVE-2019-10747 nodejs-set-value: prototype pollution in function set-value
A vulnerability was found in NOdejs set-value, where set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
Reference:
https://snyk.io/vuln/SNYK-JS-SETVALUE-450213
https://lists.apache.org/thread.html/b46f35559c4a97cf74d2dd7fe5a48f8abf2ff37f879083920af9b292@%3Cdev.drat.apache.org%3E
Discussion:
Created nodejs-set-value tracking bugs for this issue:
Affects: fedora-all [bug 1795480]
---
Red Hat Quay 3.2 uses nodejs-set-value 2.0.1 which has a fix for this vulnerability.
---
Statement:
While OpenShift Container Platform (OCP) cont
Bugzilla
CVE-2019-19919 nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads
bugzilla·2020-01-10·CVSS 9.1
CVE-2019-19919 [CRITICAL] CVE-2019-19919 nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads
CVE-2019-19919 nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Reference:
https://www.npmjs.com/advisories/1164
Discussion:
Created nodejs-handlebars tracking bugs for this issue:
Affects: epel-6 [bug 1789961]
Affects: epel-7 [bug 1789962]
Affects: fedora-all [bug 1789960]
---
i really wonder about CVE bugs getting reported since a year for various packages related to me. First they got reported then priority set low then discovered not present in one by one distribution and the
Bugzilla
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
bugzilla·2019-08-09·CVSS 9.1
CVE-2019-10744 [CRITICAL] CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Upstream Issue:
https://github.com/lodash/lodash/issues/4348
Discussion:
Created nodejs-lodash tracking bugs for this issue:
Affects: epel-all [bug 1739502]
---
This issue has been addressed in the following products:
Red Hat Virtualization Engine 4.3
Via RHSA-2019:3024 https://access.redhat.com/errata/RHSA-2019:3024
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-10
Bugzilla
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties [epel-all]
bugzilla·2019-08-09·CVSS 9.1
CVE-2019-10744 [CRITICAL] CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties [epel-all]
CVE-2019-10744 nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
arXiv
The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
arxiv_fulltext·2025-10-20
The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
The Hidden Dangers of Public Serverless Repositories: An Empirical Security Assessment
The Hidden Dangers of Public Serverless Repositories
Eduard Marin1( )
Jinwoo Kim2
Alessio Pavoni1
Mauro Conti3,4
Roberto Di Pietro5
E.\ Marin et al.
Telefonica Research, Spain
\eduard.marinfabregas, alessio.pavoni\@telefonica.com
Kwangwoon University, Republic of Korea
[email protected]
University of Padua, Italy
[email protected]
Örebro University, Sweden
King Abdullah University of Science and Technology, Saudi Arabia
[email protected]
## Abstract
Serverless computing has rapidly emerged as a prominent cloud paradigm, enabling developers to focus solely on application logic without the burden of managing servers or underlying infrastructure. Public serverless repositories
arXiv
Vulnerability Analysis of 2500 Docker Hub Images
arxiv_fulltext·2020-06-11
Vulnerability Analysis of 2500 Docker Hub Images
Vulnerability Analysis of 2500 Docker Hub Images
Katrine Wist
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Malene Helsem
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Danilo Gligoroski
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
## Abstract
The use of container technology has skyrocketed during the last few years, with Docker as the leading container platform. Docker's online repository for publicly available container images, called Docker Hub, hosts over 3.5 million images at the time of writing, making it the world's largest community of container images. We pe
https://access.redhat.com/errata/RHSA-2019:3024https://security.netapp.com/advisory/ntap-20191004-0005/https://snyk.io/vuln/SNYK-JS-LODASH-450202https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSShttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://access.redhat.com/errata/RHSA-2019:3024https://security.netapp.com/advisory/ntap-20191004-0005/https://snyk.io/vuln/SNYK-JS-LODASH-450202https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSShttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2019-07-26
Published