alibaba / alibaba/Sentinel

lodash:4.17.15组件存在CVE-2020-8203漏洞建议升级

Open
#1,762 0 comments 0 reactions 0 assignees View on GitHub
area/dashboard good first issue
Dominant language
Java
Stars
23.1k
Forks
8.1k
PR merge metrics
No merged PRs in 30d

Description

https://github.com/alibaba/Sentinel/blob/55a8294ab0afb08c6c048e541cf8a99c49069dac/sentinel-dashboard/src/main/webapp/resources/package-lock.json#L2418-L2421

推荐升级版本:
4.17.20

Contributor guide

Open the contributing guide

Research direction

Start with sentinel-dashboard/src/main/webapp/resources/package-lock.json at lines 2418-2421 and inspect the lodash dependency entry. Update the recorded version to 4.17.20, then verify that the dashboard dependency metadata remains consistent and the vulnerability is no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.