Vulnerabilities > CVE-2024-38986 - Unspecified vulnerability in 75Lb Deep-Merge 1.1.1

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
75lb
critical

Summary

Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.

Vulnerable Configurations

Part Description Count
Application
75Lb
1