Executive brief
Lodash is a widely-used JavaScript utility library that provides functions for working with objects and arrays. Versions before 4.17.5 contain a prototype pollution vulnerability in the merge, mergeWith, and defaultsDeep functions, allowing an attacker with access to these functions to inject malicious properties into all JavaScript objects in an application, potentially compromising data integrity and enabling privilege escalation.
Technical details
This is a prototype pollution vulnerability in lodash's merge-related functions (merge, mergeWith, and defaultsDeep). The vulnerable code fails to sanitize the __proto__ property when merging objects, allowing an attacker to modify the Object prototype chain. The vulnerability requires the attacker to have control over input passed to these vulnerable functions (typically via network requests or application inputs). By injecting a malicious __proto__ property into merge payloads, an attacker can add or modify properties on the prototype that will exist on all subsequent object instances, potentially leading to authentication bypass, property injection, or other logic manipulation. The fix, released in version 4.17.5, explicitly avoids merging properties onto __proto__ objects.
Affected products
- lodash lodash before 4.17.5
- lodash-rails lodash-rails before 4.17.5
Timeline
- 2018-06-07: disclosed: NVD published
- 2018-07-26: advisory: GHSA advisory published
- 2018: patched: Fixed in version 4.17.5