aws-amplify / aws-amplify/amplify-cli-export-construct

lodash.set vulnerability

Open
#99 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
13
Forks
16
PR merge metrics
No merged PRs in 30d

Description

I'm using version 0.0.6 (most current) and getting this high severity vulnerability.

lodash.set *
Severity: high
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
No fix available
node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set
@aws-amplify/cdk-exported-backend *
Depends on vulnerable versions of lodash.set
Depends on vulnerable versions of uuid
node_modules/@aws-amplify/cdk-exported-backend

I see that this vulnerability has been fixed but the release hasn't been released. Is there a plan to release this?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.