flamencist / flamencist/SelectorGenerator

CVE-2018-16487 (Medium) detected in lodash-1.0.2.tgz

Open
#2 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
20
Forks
7
PR merge metrics
No merged PRs in 30d

Description

## CVE-2018-16487 - Medium Severity Vulnerability
Vulnerable Library - lodash-1.0.2.tgz

A utility library delivering consistency, customization, performance, and extras.


Library home page: https://registry.npmjs.org/lodash/-/lodash-1.0.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/globule/node_modules/lodash/package.json


Dependency Hierarchy:
- gulp-3.9.1.tgz (Root Library)
- vinyl-fs-0.3.14.tgz
- glob-watcher-0.0.6.tgz
- gaze-0.5.2.tgz
- globule-0.1.0.tgz
- :x: **lodash-1.0.2.tgz** (Vulnerable Library)

Found in HEAD commit: dc2f1b08ce7e752558190e9785094a6975b614fd



Vulnerability Details



A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

Publish Date: 2019-02-01

URL: CVE-2018-16487



CVSS 3 Score Details (5.6)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://hackerone.com/reports/380873


Release Date: 2019-02-01


Fix Resolution (lodash): 4.17.11


Direct dependency fix Resolution (gulp): 4.0.0

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with /package.json and inspect the dependency hierarchy from gulp-3.9.1 through globule to lodash-1.0.2. Determine whether the direct gulp upgrade to 4.0.0 removes the vulnerable transitive lodash version; done means the vulnerable dependency is no longer present and the project still works.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.