New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: prototype pollution in several npm packages #4337
fix: prototype pollution in several npm packages #4337
Conversation
@@ -1001,7 +1001,7 @@ function baseMergeDeep(object, source, key, srcIndex, mergeFunc, customizer, sta | |||
if (isArguments(objValue)) { | |||
newValue = toPlainObject(objValue); | |||
} | |||
else if (!isObject(objValue) || (srcIndex && isFunction(objValue))) { | |||
else if (!isObject(objValue) || isFunction(objValue)) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is backport from new version https://github.com/snyk/lodash/blob/4.17.12-pre/lodash.js#L3668
@@ -1001,7 +1001,7 @@ function baseMergeDeep(object, source, key, srcIndex, mergeFunc, customizer, sta | |||
if (isArguments(objValue)) { | |||
newValue = toPlainObject(objValue); | |||
} | |||
else if (!isObject(objValue) || (srcIndex && isFunction(objValue))) { | |||
else if (!isObject(objValue) || isFunction(objValue)) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is backport from new version https://github.com/snyk/lodash/blob/4.17.12-pre/lodash.js#L3668
* @returns {*} Returns the property value. | ||
*/ | ||
function safeGet(object, key) { | ||
if (key === 'constructor' && typeof object[key] === 'function') { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is fix from the other PR: #4336
@@ -1146,8 +1166,8 @@ function baseMerge(object, source, srcIndex, customizer, stack) { | |||
* counterparts. | |||
*/ | |||
function baseMergeDeep(object, source, key, srcIndex, mergeFunc, customizer, stack) { | |||
var objValue = object[key], | |||
srcValue = source[key], | |||
var objValue = safeGet(object, key), |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is backport from new version: https://github.com/snyk/lodash/blob/4.17.12-pre/lodash.js#L3624
Thank you @Kirill89! |
The PR is fixing a Prototype Pollution vulnerability in:
You can see details about similar vulnerability here: https://snyk.io/vuln/SNYK-JS-LODASH-73638