Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Volnerability in Vorpal - Regular Expression Denial of Service (ReDoS) in old lodash #1278

Open
OZZlE opened this issue Jul 31, 2024 · 2 comments
Labels

Comments

@OZZlE
Copy link

OZZlE commented Jul 31, 2024

lodash  <=4.17.20
Severity: critical
Regular Expression Denial of Service (ReDoS) in lodash - https://github.com/advisories/GHSA-x5rq-j2xg-h7qm
Prototype Pollution in lodash - https://github.com/advisories/GHSA-4xc9-xhrj-v574
Regular Expression Denial of Service (ReDoS) in lodash - https://github.com/advisories/GHSA-29mw-wpgm-hmr9
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
Command Injection in lodash - https://github.com/advisories/GHSA-35jh-r3h4-6jhm
Prototype Pollution in lodash - https://github.com/advisories/GHSA-fvqr-27wr-82fm
Prototype Pollution in lodash - https://github.com/advisories/GHSA-jf85-cpcp-j695
Will install @frctl/[email protected], which is outside the stated dependency range
node_modules/vorpal/node_modules/inquirer/node_modules/lodash
  inquirer  <=0.11.4
  Depends on vulnerable versions of lodash
  node_modules/vorpal/node_modules/inquirer
    vorpal  *
    Depends on vulnerable versions of inquirer
    node_modules/vorpal

I updated to the latest versions but latest fractal still has the old version of lodash with the volnrability

@OZZlE OZZlE added the bug label Jul 31, 2024
@OZZlE
Copy link
Author

OZZlE commented Jul 31, 2024

GHSA-x5rq-j2xg-h7qm

@OZZlE
Copy link
Author

OZZlE commented Jul 31, 2024

I would be so happy if this fix could be made supporting "@frctl/nunjucks": "^1.0.3", because we have hundreds of components and would take considerable time to redo them all for nunjucks v2

@OZZlE OZZlE changed the title Regular Expression Denial of Service (ReDoS) in lodash Critical Volnerability in Vorpal - Regular Expression Denial of Service (ReDoS) in old lodash Aug 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant