Vulnerability Name:

CVE-2018-3721 (CCN-144603)

Assigned:2017-12-28
Published:2018-04-25
Updated:2019-10-03
Summary:lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2018-3721

Source: CCN
Type: IBM Security Bulletin 744553 (Voice Gateway)
Multiple vulnerabilities affect IBM Voice Gateway

Source: XF
Type: UNKNOWN
nodejs-cve20183721-sec-bypass(144603)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/lodash/lodash/commit/d8e069cc3410082e44eb18fcf8e7f3d08ebe1d4a

Source: MISC
Type: Exploit, Third Party Advisory
https://hackerone.com/reports/310443

Source: CCN
Type: Node Security Web site
lodash

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20190919-0004/

Source: CCN
Type: IBM Security Bulletin 882762 (API Connect)
IBM API Connect is affected by vulnerabilities in Node JS modules (CVE-2018-3721 CVE-2016-10531)

Source: CCN
Type: IBM Security Bulletin 885478 (API Connect)
IBM API Connect V5 is impacted by Cross Site Scripting vulnerability (CVE-2016-10531 CVE-2018-3721 CVE-2017-0268)

Source: CCN
Type: IBM Security Bulletin 6214472 (Planning Analytics Local)
IBM Planning Analytics Workspace is affected by security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6524700 (Planning Analytics Workspace)
IBM Planning Analytics Workspace is affected by security vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6551876 (Cloud Pak for Security)
Cloud Pak for Security uses packages that are vulnerable to multiple CVEs

Source: CCN
Type: IBM Security Bulletin 6565389 (WebSphere Service Registry and Repository)
Multiple vulnerabilities in WebSphere Service Registry and Repository in packages such as Apache Struts and Node.js

Source: CCN
Type: IBM Security Bulletin 6574021 (Process Mining)
Vulnerability in Lodash affects IBM Process Mining (Multiple CVEs)

Source: CCN
Type: IBM Security Bulletin 6575667 (Spectrum Discover)
High severity vulnerabilities in libraries used by IBM Spectrum Discover (libraries of libraries)

Source: CCN
Type: IBM Security Bulletin 6598689 (Tivoli Netcool/OMNIbus WebGUI)
Vulnerabilities in lodash library affect Tivoli Netcool/OMNIbus WebGUI (CVE-2019-1010266, CVE-2020-28500, CVE-2018-16487, CVE-2018-3721, CVE-2020-8203, CVE-2021-23337, CVE-2019-10744)

Source: CCN
Type: IBM Security Bulletin 6830017 (QRadar Pulse App)
QRadar Pulse application add on to IBM QRadar SIEM is vulnerable to using components with known vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6857863 (MobileFirst Platform Foundation)
Multiple vulnerabilities found on thirdparty libraries used by IBM MobileFirst Platform

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lodash:lodash:*:*:*:*:*:node.js:*:* (Version < 4.17.5)

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_service_registry_and_repository:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:5.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:nodejs:node.js:*:*:*:*:-:*:*:*
  • OR cpe:/a:ibm:api_connect:2018.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:voice_gateway:1.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:voice_gateway:1.0.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:5.0.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:planning_analytics_local:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:api_connect:2018.4.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:mobilefirst_platform_foundation:8.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:planning_analytics_workspace:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus_webgui:8.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.disco:def:201837210000000
    V
    CVE-2018-3721 on Ubuntu 19.04 (disco) - untriaged.
    2018-06-07
    oval:com.ubuntu.bionic:def:201837210000000
    V
    CVE-2018-3721 on Ubuntu 18.04 LTS (bionic) - untriaged.
    2018-06-07
    oval:com.ubuntu.xenial:def:201837210000000
    V
    CVE-2018-3721 on Ubuntu 16.04 LTS (xenial) - untriaged.
    2018-06-07
    oval:com.ubuntu.artful:def:20183721000
    V
    CVE-2018-3721 on Ubuntu 17.10 (artful) - untriaged.
    2018-06-06
    oval:com.ubuntu.cosmic:def:201837210000000
    V
    CVE-2018-3721 on Ubuntu 18.10 (cosmic) - untriaged.
    2018-06-06
    oval:com.ubuntu.bionic:def:20183721000
    V
    CVE-2018-3721 on Ubuntu 18.04 LTS (bionic) - untriaged.
    2018-06-06
    oval:com.ubuntu.cosmic:def:20183721000
    V
    CVE-2018-3721 on Ubuntu 18.10 (cosmic) - untriaged.
    2018-06-06
    oval:com.ubuntu.xenial:def:20183721000
    V
    CVE-2018-3721 on Ubuntu 16.04 LTS (xenial) - untriaged.
    2018-06-06
    BACK
    lodash lodash *
    ibm websphere service registry and repository 8.5
    ibm api connect 5.0.0.0
    nodejs node.js *
    ibm api connect 2018.1
    ibm voice gateway 1.0.0.0
    ibm voice gateway 1.0.0.7
    ibm api connect 5.0.8.6
    ibm planning analytics local 2.0
    ibm api connect 2018.4.1.4
    ibm mobilefirst platform foundation 8.0.0
    ibm cloud pak for security 1.7.2.0
    ibm planning analytics workspace 2.0
    ibm tivoli netcool/omnibus webgui 8.1.0