VDB
Sign up
MEDIUM6.5

GHSA-x5rq-j2xg-h7qm

Regular Expression Denial of Service (ReDoS) in lodash

Quick fix

GHSA-x5rq-j2xg-h7qm — lodash: upgrade to the fixed version with the command below.

npm install lodash@4.17.11

Details

lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/lodash
Introduced in: 4.7.0Fixed in: 4.17.11
Fixnpm install lodash@4.17.11
npm/lodash-es
Introduced in: 4.7.0Fixed in: 4.17.11
Fixnpm install lodash-es@4.17.11
npm/lodash-amd
Introduced in: 4.7.0Fixed in: 4.17.11
Fixnpm install lodash-amd@4.17.11
RubyGems/lodash-rails
Introduced in: 4.7.0Fixed in: 4.17.11
Fixbundle update lodash-rails

References