CVE-2019-10744 describes a critical Prototype Pollution vulnerability in lodash versions prior to 4.17.12, specifically within the defaultsDeep function, which allows attackers to manipulate Object.prototype properties. This vulnerability carries a CVSS score of 9.1 (Critical) due to its network-based attack vector, low attack complexity, and high impact on integrity and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape. Affected products include f5, lodash, NetApp, Oracle, and Red Hat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.17.12CPE matchmatch criteria | cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:service_level_manager:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.