Skip to content

Command injection vulnerability in lodash #3225

Closed
@sergibondarenko

Description

@sergibondarenko

https://www.npmjs.com/advisories/1673

Overview
lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Remediation
Upgrade to version 4.17.21 or later

Resources
CVE https://nvd.nist.gov/vuln/detail/CVE-2021-23337
GitHub Advisory GHSA-35jh-r3h4-6jhm
Snyk Advisory https://snyk.io/vuln/SNYK-JS-LODASH-1040724

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions