Skip to content

Security vulnerability found for dependency lodash #639

@acazacu

Description

@acazacu

The current release has a lodash dependency set to a fixed version. This version of lodash seems have a high severity security vulnerability.

lodash should be updated to fix the reported vulnerability.

CVE-2019-10744
More information
high severity
Vulnerable versions: < 4.17.13
Patched version: 4.17.13

Affected versions of lodash are vulnerable to Prototype Pollution.
The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions