Description
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Reroute Email Cross-Site Request Forgery (1.4.6)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5624)
Oracle Database Server CVE-2014-6455 Vulnerability (CVE-2014-6455)
WordPress Plugin DW Question & Answer Cross-Site Request Forgery (1.5.7)
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977)