-
Notifications
You must be signed in to change notification settings - Fork 293
Closed
Description
Hi, I am using Snyk to find vulnerabilities in my code.
This is what I got from running the scan on my code:
lodash.set Prototype Pollution
VULNERABILITY
CWE-400
CVSS 7.3 HIGH
SNYK-JS-LODASHSET-1320032
SCORE
472
Introduced through
[email protected]
Detailed paths
Introduced through: [email protected] › [email protected] › lodash.set@4.3.2
Fix: No remediation path available.
Overview
lodash.set is a lodash method _.set exported as a Node.js module.
Affected versions of this package are vulnerable to Prototype Pollution via the setWith and set functions.
Can you assist?
Thanks
Metadata
Metadata
Assignees
Labels
No labels