Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added vuln #36

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

Added vuln #36

wants to merge 1 commit into from

Conversation

altearjen
Copy link

No description provided.

@semgrep-code-atearjen
Copy link

Semgrep found 1 ssc-a4fd0e64-ce76-449c-8e09-743db9edce4e finding:

Risk: lodash 4.17.x before 4.17.12, lodash.defaultsdeep 4.6.x before 4.6.1, lodash.mergewith 4.6.x before 4.6.2, lodash.merge 4.6.x before 4.6.2, and lodash.template 4.5.x before 4.5.0 are vulnerable to improper input validation. Several lodash methods unsafely perform object merges, allowing user input to override object prototypes. Upgrade to lodash 4.17.12, lodash.defaultsdeep 4.6.1, lodash.mergewith 4.6.2, lodash.merge 4.6.2, or lodash.template 4.5.0.

Fix: Upgrade this library to at least version 4.17.12 at nodejs-goof/package-lock.json:16106.

Reference(s): GHSA-jf85-cpcp-j695, CVE-2019-10744

Ignore this finding from ssc-a4fd0e64-ce76-449c-8e09-743db9edce4e.

Semgrep found 1 ssc-29317a8b-48ec-4715-9dc0-a658e559fa23 finding:

Risk: Affected versions of lodash are vulnerable to Uncontrolled Resource Consumption. Vulnerable functions allow a malicious user to cause the addition or modification of an existing proprty that exists on all objects.

Fix: Upgrade this library to at least version 4.17.11 at nodejs-goof/package-lock.json:16106.

Reference(s): GHSA-4xc9-xhrj-v574, CVE-2018-16487

Ignore this finding from ssc-29317a8b-48ec-4715-9dc0-a658e559fa23.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant