Skip to content

There is a vulnerability in lodash 4.17.20 ,upgrade recommended #15363

@QiAnXinCodeSafe

Description

@QiAnXinCodeSafe

airflow/airflow/www/yarn.lock

Lines 4490 to 4493 in 7490c6b

lodash@^4.17.20, lodash@^4.17.5, lodash@~4.17.19:
version "4.17.20"
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.20.tgz#b44a9b6297bcb698f1c51a3545a2b3b368d59c52"
integrity sha512-PlhdFcillOINfeV7Ni6oF1TAEayyZBoZ8bcshTHqOYJYlrqzRK5hagpagky5o4HfCzzd1TRkXPMFq6cKk9rGmA==

CVE-2021-23337 CVE-2020-28500

Recommended upgrade version:4.17.21

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions