CVE-2019-10744
9.1
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 5.01% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-1321 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-26 |
| Last modified | 2026-06-17 |
Affected (21)
| Vendor | Product |
|---|---|
| f5 | big-ip access policy manager |
| f5 | big-ip advanced firewall manager |
| f5 | big-ip analytics |
| f5 | big-ip application acceleration manager |
| f5 | big-ip application security manager |
| f5 | big-ip application visibility and reporting |
| f5 | big-ip domain name system |
| f5 | big-ip edge gateway |
| f5 | big-ip fraud protection service |
| f5 | big-ip global traffic manager |
| f5 | big-ip link controller |
| f5 | big-ip local traffic manager |
| f5 | big-ip policy enforcement manager |
| f5 | big-ip webaccelerator |
| f5 | big-iq centralized management |
| f5 | iworkflow |
| lodash | lodash |
| netapp | active iq unified manager |
| netapp | service level manager |
| oracle | banking extensibility workbench |
| redhat | virtualization manager |
References
- https://access.redhat.com/errata/RHSA-2019:3024
- https://security.netapp.com/advisory/ntap-20191004-0005/
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSS
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://access.redhat.com/errata/RHSA-2019:3024
- https://security.netapp.com/advisory/ntap-20191004-0005/
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://support.f5.com/csp/article/K47105354?utm_source=f5support&%3Butm_medium=RSS
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
→ the Explorer · watch your stack · NVD