Lodash Vulnerability
See original GitHub issueThe package.json
file in this repo references an insecure version of lodash and should be updated at least to version 4.17.5.
Ref: https://nvd.nist.gov/vuln/detail/CVE-2018-3721
Is there any progress on PR #48?
Issue Analytics
- State:
- Created 5 years ago
- Reactions:23
- Comments:5
Top Results From Across the Web
lodash vulnerabilities | Snyk
version published direct vulnerabilities
4.17.21 20 Feb, 2021 0. C. 0. H. 0. M. 0. L
4.17.20 13 Aug, 2020 0. C. 1. H. 1....
Read more >Lodash : Security vulnerabilities - CVE Details
# CVE ID CWE ID Vulnerability Type(s) Publish Date Update Date Score Gaine...
1 CVE‑2021‑23337 94 2021‑02‑15 2022‑09‑13 6.5 None
2 CVE‑2020‑28500 DoS 2021‑02‑15 2022‑09‑13...
Read more >Lodash: Understanding the recent ... - DEV Community
Lodash versions prior to 4.17.19 are vulnerable to a Prototype Pollution (CVE-2020-8203). The function zipObjectDeep() allows a malicious user ...
Read more >Security Bulletin: Lodash versions prior to 4.17.21 vulnerability ...
DESCRIPTION: Node.js lodash module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) in the ...
Read more >Lodash: Understanding the recent vulnerability and how we ...
Lodash versions prior to 4.17.19 are vulnerable to a Prototype Pollution (CVE-2020-8203). The function zipObjectDeep() allows a malicious user to modify the ...
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Just found out this, for anyone looking for a consistent solution for signing URL in a production reliable way:
https://github.com/jasonsims/aws-cloudfront-sign/pull/52#issuecomment-524302869
Seriously, this issue is here for two years and no action was taken. The vulnerability is critical, lodash must be updated ASAP.