First published: Wed Jul 17 2019(Updated: )
Lodash is vulnerable to a denial of service, caused by uncontrolled resource consumption in Date handler. By sending an overly long string, a local attacker could exploit this vulnerability to cause the application to stop responding.
Credit: josh@bress.net
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Verify Governance | <=10.0 | |
redhat/lodash | <4.7.11 | 4.7.11 |
Lodash Lodash Node.js | <4.17.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1010266 is a vulnerability in Lodash that can be exploited by a local attacker to cause a denial of service.
CVE-2019-1010266 is caused by uncontrolled resource consumption in the Date handler of Lodash, which allows an attacker to crash the application by sending an overly long string.
CVE-2019-1010266 has a severity rating of medium (4) due to the potential denial of service impact.
Lodash version 4.7.11 is affected by CVE-2019-1010266. IBM Security Verify Governance versions up to and including 10.0 are also affected.
To fix CVE-2019-1010266, update Lodash to version 4.7.11 or higher. For IBM Security Verify Governance, update to a version higher than 10.0.