Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| lodash(npm) | 3.7.0 | 4.17.19 | N/A |
| lodash-es(npm) | 3.7.0 | 4.17.20 | N/A |
| lodash.pick(npm) | 4.0.0 | N/A | N/A |
| lodash.set(npm) | 3.7.0 | N/A | N/A |
| lodash.setwith(npm) | 0 | N/A | N/A |
| lodash.update(npm) | 0 | N/A | N/A |
| lodash.updatewith(npm) | 0 | N/A | N/A |
| lodash-rails(RubyGems) | 3.7.0 | 4.17.19 | N/A |
CVSS Metrics