aws-amplify / aws-amplify/amplify-cli-export-construct

lodash.set vulnerability

Offen
#99 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
TypeScript
Sterne
13
Forks
16
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

I'm using version 0.0.6 (most current) and getting this high severity vulnerability.

lodash.set *
Severity: high
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
No fix available
node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set
@aws-amplify/cdk-exported-backend *
Depends on vulnerable versions of lodash.set
Depends on vulnerable versions of uuid
node_modules/@aws-amplify/cdk-exported-backend

I see that this vulnerability has been fixed but the release hasn't been released. Is there a plan to release this?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the reported dependency path, node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set, and review how @aws-amplify/cdk-exported-backend and uuid are pinned. Check the package metadata and release process to determine what change is needed; done means the published dependency tree no longer reports the stated lodash.set vulnerability.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
typescript
Bereich
release, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.