Skip to content

Conversation

@TeodorBucht1729
Copy link

@TeodorBucht1729 TeodorBucht1729 commented Jul 1, 2021

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

Read more at Debricked: https://app.debricked.com/en/service/vulnerability/118293

@TeodorBucht1729 TeodorBucht1729 marked this pull request as ready for review July 1, 2021 14:08
@rasmus-hagberg rasmus-hagberg force-pushed the master branch 2 times, most recently from 1347ff8 to 43f8c5d Compare February 28, 2022 13:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants