flamencist / flamencist/CopyCssSelector

CVE-2019-10744 (High) detected in multiple libraries

Open
#7 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
28
Forks
3
PR merge metrics
No merged PRs in 30d

Description

## CVE-2019-10744 - High Severity Vulnerability
Vulnerable Libraries - lodash.template-3.6.2.tgz, lodash-1.0.2.tgz, lodash-3.3.0.tgz


lodash.template-3.6.2.tgz

The modern build of lodash’s `_.template` as a module.


Library home page: https://registry.npmjs.org/lodash.template/-/lodash.template-3.6.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/lodash.template/package.json


Dependency Hierarchy:
- gulp-3.9.1.tgz (Root Library)
- gulp-util-3.0.8.tgz
- :x: **lodash.template-3.6.2.tgz** (Vulnerable Library)


lodash-1.0.2.tgz

A utility library delivering consistency, customization, performance, and extras.


Library home page: https://registry.npmjs.org/lodash/-/lodash-1.0.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/globule/node_modules/lodash/package.json


Dependency Hierarchy:
- gulp-3.9.1.tgz (Root Library)
- vinyl-fs-0.3.14.tgz
- glob-watcher-0.0.6.tgz
- gaze-0.5.2.tgz
- globule-0.1.0.tgz
- :x: **lodash-1.0.2.tgz** (Vulnerable Library)


lodash-3.3.0.tgz

The modern build of lodash modular utilities.


Library home page: https://registry.npmjs.org/lodash/-/lodash-3.3.0.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/node-rsa/node_modules/lodash/package.json


Dependency Hierarchy:
- gulp-crx-pack-1.0.2.tgz (Root Library)
- crx-3.2.1.tgz
- node-rsa-0.2.30.tgz
- :x: **lodash-3.3.0.tgz** (Vulnerable Library)

Found in HEAD commit: 04bcf32bddc1419e0013d468c6018209aa2b6291



Vulnerability Details



Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Publish Date: 2019-07-26

URL: CVE-2019-10744



CVSS 3 Score Details (9.1)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://github.com/advisories/GHSA-jf85-cpcp-j695


Release Date: 2019-07-26


Fix Resolution (lodash.template): 4.5.0


Direct dependency fix Resolution (gulp): 4.0.0

Fix Resolution (lodash): 4.17.12


Direct dependency fix Resolution (gulp): 4.0.0

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with package.json and compare the dependency hierarchy and suggested resolutions for gulp, lodash.template, and lodash. Check the HEAD commit referenced in the report, then verify that the vulnerable versions are no longer present and that the project still builds as a Chrome extension.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.