lodash Vulnerability
See original GitHub issueExpected Behavior
yarn audit
shouldn’t return any audit problems
Actual Behavior
yarn audit
returns High vulnerability
More info
https://www.npmjs.com/advisories/1065
Possible Solution
Upgrade lodash
Steps to Reproduce
- yarn audit / npm audit
Context
Currently breaks CI as we rely on audits
Environment
- Node Version: v10.14.1
- Package Manager Version: 6.4.1
- Operating System: 18.6.0 Darwin Kernel Version 18.6.0: Thu Apr 25 23:16:27 PDT 2019; root:xnu-4903.261.4~2/RELEASE_X86_64 x86_64
- Package Version: 3.0.4
Issue Analytics
- State:
- Created 4 years ago
- Reactions:4
- Comments:7 (4 by maintainers)
Top Results From Across the Web
lodash vulnerabilities | Snyk
version published direct vulnerabilities
4.17.21 20 Feb, 2021 0. C. 0. H. 0. M. 0. L
4.17.20 13 Aug, 2020 0. C. 1. H. 1....
Read more >Lodash : Security vulnerabilities - CVE Details
# CVE ID CWE ID Vulnerability Type(s) Publish Date Update Date Score Gaine...
1 CVE‑2021‑23337 94 2021‑02‑15 2022‑09‑13 6.5 None
2 CVE‑2020‑28500 DoS 2021‑02‑15 2022‑09‑13...
Read more >Lodash: Understanding the recent ... - DEV Community
Lodash versions prior to 4.17.19 are vulnerable to a Prototype Pollution (CVE-2020-8203). The function zipObjectDeep() allows a malicious user ...
Read more >Security Bulletin: Lodash versions prior to 4.17.21 vulnerability ...
DESCRIPTION: Node.js lodash module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) in the ...
Read more >Lodash: Understanding the recent vulnerability and how we ...
Lodash versions prior to 4.17.19 are vulnerable to a Prototype Pollution (CVE-2020-8203). The function zipObjectDeep() allows a malicious user to modify the ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
@petercooperjr-spls Sorry due to some issues in CI, 3.0.5 publish failed. We just fixed this and published 3.0.5, please check.
Thanks for working with Microsoft on GitHub! Tell us how you feel about your experience using the reactions on this comment.