mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 17:50:34 +00:00
43 lines
1.9 KiB
Markdown
43 lines
1.9 KiB
Markdown
![]() |
### [CVE-2019-10744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10744)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
|
||
|
- https://www.oracle.com/security-alerts/cpujan2021.html
|
||
|
- https://www.oracle.com/security-alerts/cpuoct2020.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/A2u13/JS-Security
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/HotDB-Community/HotDB-Engine
|
||
|
- https://github.com/JoBrad/casefold
|
||
|
- https://github.com/Kirill89/Kirill89
|
||
|
- https://github.com/MaySoMusician/geidai-ikoi
|
||
|
- https://github.com/NetSPI/npm-deps-parser
|
||
|
- https://github.com/azuqua/cassanknex
|
||
|
- https://github.com/chkp-dhouari/CloudGuard-ShiftLeft-CICD
|
||
|
- https://github.com/cristianstaicu/SecBench.js
|
||
|
- https://github.com/dcambronero/shiftleft
|
||
|
- https://github.com/duckstroms/Web-CTF-Cheatsheet
|
||
|
- https://github.com/endorama/CsvToL10nJson
|
||
|
- https://github.com/nVisium/npm-deps-parser
|
||
|
- https://github.com/nilsujma-dev/CloudGuard-ShiftLeft-CICD
|
||
|
- https://github.com/ossf-cve-benchmark/CVE-2019-10744
|
||
|
- https://github.com/p3sky/Cloudguard-Shifleft-CICD
|
||
|
- https://github.com/puryersc/shiftleftv2
|
||
|
- https://github.com/puryersc/shiftleftv3
|
||
|
- https://github.com/puryersc/shiftleftv4
|
||
|
- https://github.com/ray-tracer96024/Unintentionally-Vulnerable-Hotel-Management-Website
|
||
|
- https://github.com/seal-community/patches
|
||
|
- https://github.com/vulna-felickz/js-security-updates-nolock
|
||
|
- https://github.com/w181496/Web-CTF-Cheatsheet
|
||
|
|