PT-2024-28302 · Lodash+1 · Lodash+1

Published

2024-07-30

·

Updated

2024-08-08

·

CVE-2024-38986

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 75lb deep-merge version 1.1.1
Description The issue allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and have other impacts via merge methods of lodash to merge objects. This is due to Prototype Pollution in the affected software.
Recommendations For version 1.1.1, consider disabling the merge methods of lodash to minimize the risk of exploitation until a patch is available. Restrict the use of the deep-merge function to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-38986
GHSA-28MC-G557-92M7

Affected Products

75Lb Deep-Merge
Lodash