Description
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.
Remediation
References
Related Vulnerabilities
TYPO3 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2010-3663)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.31)
WordPress Plugin Flog Cross-Site Scripting (0.1)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2019-5482)
Moodle Improper Input Validation Vulnerability (CVE-2009-1171)