Capgemini / Capgemini/powerapps-specflow-bindings

Vulnerability: lodash-4.17.20.js

Open
#123 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C#
Stars
42
Forks
27
PR merge metrics
No merged PRs in 30d

Description

Vulnerability | Library | Description | Top Fix
-- | -- | -- | --
High7.2CVE-2021-23337Feb-15-2021 | lodash-4.17.20.js | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Upgrade to version lodash - 4.17.21https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
Medium5.3CVE-2020-28500Feb-15-2021 | lodash-4.17.20.js | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. Mend Note: After conducting further research, Mend has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash. | Upgrade to version lodash - 4.17.21https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500
Medium5.3CVE-2020-28500Feb-15-2021 | lodash-4.17.20.min.js | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. Mend Note: After conducting further research, Mend has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash. | Upgrade to version lodash - 4.17.21https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.