peter bassill · operator
$ cve CVE-2019-10744 JSON

CVE-2019-10744

9.1
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS5.01% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-1321
On CISA KEVno
Public exploitnone known
Published2019-07-26
Last modified2026-06-17

Affected (21)

VendorProduct
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip application visibility and reporting
f5big-ip domain name system
f5big-ip edge gateway
f5big-ip fraud protection service
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip webaccelerator
f5big-iq centralized management
f5iworkflow
lodashlodash
netappactive iq unified manager
netappservice level manager
oraclebanking extensibility workbench
redhatvirtualization manager

References

→ the Explorer  ·  watch your stack  ·  NVD