debricked / soot-wrapper

Analyses how you use your dependencies to figure out if you use the vulnerable parts of a vulnerable dependency
MIT License
4 stars 5 forks source link

Add JavaScript compatibility to Vuln Func #5

Open TeodorBucht1729 opened 3 years ago

TeodorBucht1729 commented 3 years ago

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

Read more at Debricked: https://app.debricked.com/en/service/vulnerability/118293