CVE-2018-3721 describes a Modification of Assumed-Immutable Data (MAID) vulnerability in the lodash node module, specifically affecting versions prior to 4.17.5. This flaw, present in the defaultsDeep, merge, and mergeWith functions, allows an attacker to manipulate the prototype of the "Object" via __proto__, impacting all objects within an application utilizing affected lodash versions, including NetApp products. Rated as Medium severity with a CVSS score of 6.5, this vulnerability has a low attack complexity and requires low privileges (PR:L) but can lead to high integrity impacts (I:H) without user interaction. The potential impact is the addition or modification of existing properties across all objects, which could lead to unexpected behavior or further vulnerabilities. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.17.5CPE matchmatch criteria | cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:netapp:system_manager:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.