Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-r5fr-rjxr-66jc
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.template
lodash vulnerable to Code Injection via `_.template` imports key names 01 Apr
  • Fix available
  • Severity - 8.1 (High)
GHSA-f23m-r3pf-42rh
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.unset
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` 01 Apr
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-xxjr-mmjv-4gpg
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.unset
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions 21 Jan
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-x5rq-j2xg-h7qm
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
Regular Expression Denial of Service (ReDoS) in lodash 19 Jul 2019
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-jf85-cpcp-j695
  • RubyGems/lodash-rails
  • npm/lodash
  • npm/lodash-amd
  • npm/lodash-es
  • npm/lodash.defaultsdeep
Prototype Pollution in lodash 10 Jul 2019
  • Fix available
  • Severity - 9.1 (Critical)