lodash Prototype Pollution high security vulnerability
See original GitHub issueCheerio needs to update it’s lodash package to address the High severity vulnerability found in lodash
as per: https://snyk.io/vuln/SNYK-JS-LODASH-450202
Lodash appears to have addressed the problem w/4.17.4 as per: https://github.com/lodash/lodash/issues/4348
Issue Analytics
- State:
- Created 4 years ago
- Reactions:4
- Comments:13 (4 by maintainers)
Top Results From Across the Web
Prototype Pollution in lodash - Snyk Vulnerability Database
Prototype Pollution is a vulnerability affecting JavaScript. Prototype Pollution refers to the ability to inject properties into existing ...
Read more >Prototype Pollution in lodash · CVE-2020-8203 - GitHub
This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of...
Read more >Prototype pollution: The dangerous and underrated ...
In early 2019, security researchers at Snyk disclosed details of a severe vulnerability in Lodash, a popular JavaScript library, which allowed ...
Read more >Lodash : Security vulnerabilities - CVE Details
# CVE ID CWE ID Vulnerability Type(s) Publish Date Update Date Score Gaine...
1 CVE‑2021‑23337 94 2021‑02‑15 2022‑09‑13 6.5 None
2 CVE‑2020‑28500 DoS 2021‑02‑15 2022‑09‑13...
Read more >Lodash: Understanding the recent vulnerability and how we ...
Lodash versions prior to 4.17.19 are vulnerable to a Prototype Pollution (CVE-2020-8203). The function zipObjectDeep() allows a malicious user to modify the ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
I sat down to offer a PR for this, but it looks like cheerio’s master branch already has no non-dev “npm audit” warnings left. Any chance of a release? It’s becoming a barrier to adoption unfortunately. Appreciate your time!
I will put this on my “contribute when I’m able” list. We really value this module at ApostropheCMS!
On Thu, Aug 27, 2020 at 11:18 AM Tom Boutell tom@apostrophecms.com wrote:
–
THOMAS BOUTELL | CHIEF TECHNOLOGY OFFICER APOSTROPHECMS | apostrophecms.com | he/him/his