Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
{
"binaries": [
{
"binary_name": "libjs-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5"
},
{
"binary_name": "node-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5"
},
{
"binary_name": "node-lodash-packages",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5"
}
]
}{
"binaries": [
{
"binary_name": "libjs-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash-packages",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
}
]
}{
"binaries": [
{
"binary_name": "libjs-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash-packages",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
}
]
}{
"binaries": [
{
"binary_name": "libjs-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
},
{
"binary_name": "node-lodash-packages",
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9"
}
]
}