genius-api icon indicating copy to clipboard operation
genius-api copied to clipboard

fix: security vulnerability CVE-2018-3721

Open ShyykoSerhiy opened this issue 6 years ago • 0 comments

CVE-2018-3721 Vulnerable versions: <4.17.5 Patched version: 4.17.5 lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.

ShyykoSerhiy avatar Oct 22 '18 23:10 ShyykoSerhiy