VDB
Sign up
MEDIUM5.3

GHSA-29mw-wpgm-hmr9

Regular Expression Denial of Service (ReDoS) in lodash

Quick fix

GHSA-29mw-wpgm-hmr9 — lodash: upgrade to the fixed version with the command below.

npm install lodash@4.17.21

Details

All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `toNumber`, `trim` and `trimEnd` functions.

Steps to reproduce (provided by reporter Liyuan Chen): ```js var lo = require('lodash');

function build_blank(n) { var ret = "1" for (var i = 0; i < n; i++) { ret += " " } return ret + "1"; } var s = build_blank(50000) var time0 = Date.now(); lo.trim(s) var time_cost0 = Date.now() - time0; console.log("time_cost0: " + time_cost0); var time1 = Date.now(); lo.toNumber(s) var time_cost1 = Date.now() - time1; console.log("time_cost1: " + time_cost1); var time2 = Date.now(); lo.trimEnd(s); var time_cost2 = Date.now() - time2; console.log("time_cost2: " + time_cost2); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lodash
Introduced in: 4.0.0Fixed in: 4.17.21
Fixnpm install lodash@4.17.21
npm/lodash-es
Introduced in: 4.0.0Fixed in: 4.17.21
Fixnpm install lodash-es@4.17.21
npm/lodash.trimend
Introduced in: 4.0.0

No fixed version published yet for lodash.trimend (npm). Pin to a known-safe version or switch to an alternative.

npm/lodash.trim
Introduced in: 4.0.0

No fixed version published yet for lodash.trim (npm). Pin to a known-safe version or switch to an alternative.

RubyGems/lodash-rails
Introduced in: 4.0.0Fixed in: 4.17.21
Fixbundle update lodash-rails

References