Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
{
"binaries": [
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5",
"binary_name": "libjs-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5",
"binary_name": "node-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-5",
"binary_name": "node-lodash-packages"
}
]
}{
"binaries": [
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "libjs-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash-packages"
}
]
}{
"binaries": [
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "libjs-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash-packages"
}
]
}{
"binaries": [
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "libjs-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash"
},
{
"binary_version": "4.17.21+dfsg+~cs8.31.198.20210220-9",
"binary_name": "node-lodash-packages"
}
]
}