Skip to content
This repository has been archived by the owner on May 22, 2024. It is now read-only.

[Snyk: High] lodash command injection (due 02/03/2022) #643

Closed
1 task
Tracked by #137
pkfec opened this issue Dec 22, 2021 · 1 comment
Closed
1 task
Tracked by #137

[Snyk: High] lodash command injection (due 02/03/2022) #643

pkfec opened this issue Dec 22, 2021 · 1 comment
Assignees
Labels
Security: general General security concern or issue Security: high Remediate within 30 days
Milestone

Comments

@pkfec
Copy link
Contributor

pkfec commented Dec 22, 2021

Overview

lodash is a modern JavaScript utility library delivering modularity, performance, & extras.

Affected versions of this package are vulnerable to Command Injection via template

https://security.snyk.io/vuln/SNYK-JS-LODASH-1040724

Detailed paths:

  • Introduced through: fec-eregs@1.0.0 › node-sass@7.0.0 › lodash@4.17.19
    Fix: Your dependencies are out of date, otherwise you would be using a newer lodash than lodash@4.17.19. Try relocking your lockfile or deleting node_modules, reinstalling and running snyk wizard. If the problem persists, one of your dependencies may be bundling outdated modules.

  • Introduced through: fec-eregs@1.0.0 › node-sass@7.0.0 › sass-graph@2.2.5 › lodash@4.17.19
    Fix: Your dependencies are out of date, otherwise you would be using a newer lodash than lodash@4.17.19. Try relocking your lockfile or deleting node_modules, reinstalling and running snyk wizard. If the problem persists, one of your dependencies may be bundling outdated modules.

  • Introduced through: fec-eregs@1.0.0 › node-sass@7.0.0 › gaze@1.1.3 › globule@1.3.2 › lodash@4.17.19
    Fix: Your dependencies are out of date, otherwise you would be using a newer lodash than lodash@4.17.19. Try relocking your lockfile or deleting node_modules, reinstalling and running snyk wizard. If the problem persists, one of your dependencies may be bundling outdated modules.

Remediation:

Upgrade lodash@4.17.21

Completion criteria:

  • Upgrade lodash@4.17.21
@pkfec pkfec added Security: high Remediate within 30 days Security: general General security concern or issue labels Dec 22, 2021
@pkfec pkfec changed the title [Snyk: High] Lodash Command injection (due 02/03/2022) [Snyk: High] lodash command injection (due 02/03/2022) Dec 22, 2021
@patphongs patphongs added this to the Sprint 17.1 milestone Jan 10, 2022
@pkfec
Copy link
Contributor Author

pkfec commented Jan 20, 2022

updated lodash version to 4.17.21 in package.json.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Security: general General security concern or issue Security: high Remediate within 30 days
Projects
None yet
Development

No branches or pull requests

3 participants