-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 6.10.4
-
Component/s: Security - Other
-
None
-
Severity 3 - Minor
Issue Summary
lodash is vulnerable to prototype pollution attack. The vulnerability exists due to the ability to inject properties on Object.prototype using the function `zipObjectDeep`, leading to DoS, and possibly other forms of attacks.
More details here: https://snyk.io/vuln/SNYK-JS-LODASH-590103
Steps to Reproduce
N/A
Expected Results
N/A
Actual Results
N/A
Workaround
N/A