Description
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Remediation
References
Related Vulnerabilities
PHP Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2004-0594)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9046)
WordPress Plugin FeedList 'handler_image.php' Cross-Site Scripting (2.61.01)
WordPress Plugin YITH WooCommerce Recover Abandoned Cart Security Bypass (1.3.2)