Capgemini / Capgemini/powerapps-specflow-bindings
Vulnerability: lodash-4.17.20.js
- Dominant language
- C#
- Stars
- 42
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
Vulnerability | Library | Description | Top Fix
-- | -- | -- | --
High7.2CVE-2021-23337Feb-15-2021 | lodash-4.17.20.js | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Upgrade to version lodash - 4.17.21https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
Medium5.3CVE-2020-28500Feb-15-2021 | lodash-4.17.20.js | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. Mend Note: After conducting further research, Mend has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash. | Upgrade to version lodash - 4.17.21https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500
Medium5.3CVE-2020-28500Feb-15-2021 | lodash-4.17.20.min.js | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. Mend Note: After conducting further research, Mend has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash. | Upgrade to version lodash - 4.17.21https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500
Contributor guide
Assessment
This issue has not been assessed yet.