fix(deps): update dependency lodash to v4.17.21 [security] #18
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.10.0
->4.17.21
Prototype Pollution in lodash
CVE-2018-3721 / GHSA-fvqr-27wr-82fm
More information
Details
Versions of
lodash
before 4.17.5 are vulnerable to prototype pollution.The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of
Object
via__proto__
causing the addition or modification of an existing property that will exist on all objects.Recommendation
Update to version 4.17.5 or later.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Prototype Pollution in lodash
CVE-2018-16487 / GHSA-4xc9-xhrj-v574
More information
Details
Versions of
lodash
before 4.17.11 are vulnerable to prototype pollution.The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of
Object
via{constructor: {prototype: {...}}}
causing the addition or modification of an existing property that will exist on all objects.Recommendation
Update to version 4.17.11 or later.
Severity
High
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Regular Expression Denial of Service (ReDoS) in lodash
CVE-2019-1010266 / GHSA-x5rq-j2xg-h7qm
More information
Details
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.
Severity
Moderate
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Prototype Pollution in lodash
CVE-2019-10744 / GHSA-jf85-cpcp-j695
More information
Details
Versions of
lodash
before 4.17.12 are vulnerable to Prototype Pollution. The functiondefaultsDeep
allows a malicious user to modify the prototype ofObject
via{constructor: {prototype: {...}}}
causing the addition or modification of an existing property that will exist on all objects.Recommendation
Update to version 4.17.12 or later.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Prototype Pollution in lodash
CVE-2020-8203 / GHSA-p6mc-m468-83gw
More information
Details
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions
pick
,set
,setWith
,update
,updateWith
, andzipObjectDeep
allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays.This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Regular Expression Denial of Service (ReDoS) in lodash
CVE-2020-28500 / GHSA-29mw-wpgm-hmr9
More information
Details
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the
toNumber
,trim
andtrimEnd
functions.Steps to reproduce (provided by reporter Liyuan Chen):
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Command Injection in lodash
CVE-2021-23337 / GHSA-35jh-r3h4-6jhm
More information
Details
lodash
versions prior to 4.17.21 are vulnerable to Command Injection via the template function.Severity
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
lodash/lodash (lodash)
v4.17.21
Compare Source
v4.17.20
Compare Source
v4.17.16
Compare Source
v4.17.15
Compare Source
v4.17.14
Compare Source
v4.17.13
Compare Source
v4.17.12
Compare Source
v4.17.11
Compare Source
v4.17.10
Compare Source
v4.17.9
Compare Source
v4.17.5
Compare Source
v4.17.4
Compare Source
v4.17.3
Compare Source
v4.17.2
Compare Source
v4.17.1
Compare Source
v4.17.0
Compare Source
v4.16.6
Compare Source
v4.16.5
Compare Source
v4.16.4
Compare Source
v4.16.3
Compare Source
v4.16.2
Compare Source
v4.16.1
Compare Source
v4.16.0
Compare Source
v4.15.0
Compare Source
v4.14.2
Compare Source
v4.14.1
Compare Source
v4.14.0
Compare Source
v4.13.1
Compare Source
v4.13.0
Compare Source
v4.12.0
Compare Source
v4.11.2
Compare Source
v4.11.1
Compare Source
v4.11.0
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.