---
title: "CVE-2019-10744"
canonical: "https://kb.cynergy.app/space/MD/929234945/CVE-2019-10744"
format: markdown
---
**Description**

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

**Published On**

07/25/2019

**Updated On**

03/16/2021

**Trending**

FALSE

**CWE**


**Exploit**

[https://security.snyk.io/vuln/SNYK-JS-LODASH-450202](https://security.snyk.io/vuln/SNYK-JS-LODASH-450202) 

 

**Mitigation:**

![image](media://121f07ef-de50-4f1f-bd99-aaa8e16794e0)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Update to version 4.17.12 or later.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

**References**

|  |  |  |  |
| --- | --- | --- | --- |
| GHSA-jf85-cpcp-j695 | lodash |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash-amd |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash-es |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash.defaultsdeep |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash.merge |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash.mergewith |  | ![URL Logo]() |
| GHSA-jf85-cpcp-j695 | lodash.template |  | ![URL Logo]() |