CVE-2019-10744

Source
https://cve.org/CVERecord?id=CVE-2019-10744
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10744.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-10744
Aliases
Downstream
Published
2019-07-26T00:15:11.217Z
Modified
2026-05-28T04:04:51.662958166Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_access_policy_manager"
        },
        {
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_advanced_firewall_manager"
        },
        {
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "last_affected": "12.1.5"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "last_affected": "13.1.3"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "last_affected": "14.1.2"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.3"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "cpes": [
                "cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_analytics"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_application_acceleration_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_application_security_manager"
        },
        {
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "last_affected": "13.1.3"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:f5:big-ip_application_visibility_and_reporting:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_application_visibility_and_reporting"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_domain_name_system"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_edge_gateway"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_fraud_protection_service"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_global_traffic_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_link_controller"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_local_traffic_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_policy_enforcement_manager"
        },
        {
            "extracted_events": [
                {
                    "introduced": "12.1.0"
                },
                {
                    "fixed": "12.1.5.2"
                },
                {
                    "introduced": "13.1.0"
                },
                {
                    "fixed": "13.1.3.4"
                },
                {
                    "introduced": "14.1.0"
                },
                {
                    "fixed": "14.1.2.5"
                },
                {
                    "introduced": "15.0.0"
                },
                {
                    "fixed": "15.0.1.4"
                },
                {
                    "introduced": "15.1.0"
                },
                {
                    "fixed": "15.1.0.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-ip_webaccelerator"
        },
        {
            "extracted_events": [
                {
                    "introduced": "6.0.0"
                },
                {
                    "last_affected": "6.1.0"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-iq_centralized_management"
        },
        {
            "source": "CPE_STRING",
            "extracted_events": [
                {
                    "last_affected": "5.4.0"
                },
                {
                    "last_affected": "7.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:f5:big-iq_centralized_management:5.4.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:f5:big-iq_centralized_management:7.0.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:big-iq_centralized_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "2.3.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:f5:iworkflow:2.3.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "f5:iworkflow"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.4.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.4.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_extensibility_workbench"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "4.3"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:redhat:virtualization_manager:4.3:*:*:*:*:*:*:*"
            ],
            "vendor_product": "redhat:virtualization_manager"
        }
    ]
}
References

Affected packages

Git / github.com/lodash/lodash

Affected ranges

Type
GIT
Repo
https://github.com/lodash/lodash
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.17.12"
        }
    ]
}

Affected versions

3.*
3.0.0-npm
3.0.1-npm
3.1.0-npm
3.10.0-npm
3.10.1-npm
3.2.0-npm
3.3.0-npm
3.3.1-npm
3.4.0-npm
3.5.0-npm
3.6.0-npm
3.7.0-npm
3.8.0-npm
3.9.0-npm
3.9.1-npm
3.9.2-npm
3.9.3-npm
4.*
4.0.0-npm
4.0.1-npm
4.1.0-npm
4.10.0-npm
4.11.0-npm
4.11.1-npm
4.11.2-npm
4.12.0-npm
4.13.0-npm
4.13.1-npm
4.14.0-npm
4.14.1-npm
4.14.2-npm
4.15.0-npm
4.16.0-npm
4.16.1-npm
4.16.2-npm
4.16.3-npm
4.16.4-npm
4.16.5-npm
4.16.6-npm
4.17.0-npm
4.17.1-npm
4.17.10-npm
4.17.11-npm
4.17.2-npm
4.17.3-npm
4.17.4-npm
4.17.5-npm
4.17.9-npm
4.2.0-npm
4.2.1-npm
4.3.0-npm
4.4.0-npm
4.5.0-npm
4.5.1-npm
4.6.0-npm
4.6.1-npm
4.7.0-npm
4.8.0-npm
4.8.1-npm
4.8.2-npm
4.9.0-npm

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-10744.json"