flamencist / flamencist/SelectorGenerator

CVE-2019-10744 (High) detected in lodash.template-3.6.2.tgz, lodash-1.0.2.tgz

Open
#5 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
20
Forks
7
PR merge metrics
No merged PRs in 30d

Description

## CVE-2019-10744 - High Severity Vulnerability
Vulnerable Libraries - lodash.template-3.6.2.tgz, lodash-1.0.2.tgz


lodash.template-3.6.2.tgz

The modern build of lodash’s `_.template` as a module.


Library home page: https://registry.npmjs.org/lodash.template/-/lodash.template-3.6.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/lodash.template/package.json


Dependency Hierarchy:
- gulp-3.9.1.tgz (Root Library)
- gulp-util-3.0.8.tgz
- :x: **lodash.template-3.6.2.tgz** (Vulnerable Library)


lodash-1.0.2.tgz

A utility library delivering consistency, customization, performance, and extras.


Library home page: https://registry.npmjs.org/lodash/-/lodash-1.0.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/globule/node_modules/lodash/package.json


Dependency Hierarchy:
- gulp-3.9.1.tgz (Root Library)
- vinyl-fs-0.3.14.tgz
- glob-watcher-0.0.6.tgz
- gaze-0.5.2.tgz
- globule-0.1.0.tgz
- :x: **lodash-1.0.2.tgz** (Vulnerable Library)

Found in HEAD commit: dc2f1b08ce7e752558190e9785094a6975b614fd



Vulnerability Details



Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Publish Date: 2019-07-26

URL: CVE-2019-10744



CVSS 3 Score Details (9.1)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://github.com/advisories/GHSA-jf85-cpcp-j695


Release Date: 2019-07-26


Fix Resolution (lodash.template): 4.5.0


Direct dependency fix Resolution (gulp): 4.0.0

Fix Resolution (lodash): 4.17.12


Direct dependency fix Resolution (gulp): 4.0.0

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.