MEDIUM6.5
GHSA-x5rq-j2xg-h7qm
Regular Expression Denial of Service (ReDoS) in lodash
Quick fix
GHSA-x5rq-j2xg-h7qm — lodash: upgrade to the fixed version with the command below.
npm install lodash@4.17.11Details
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-1010266[ADVISORY]
- https://github.com/lodash/lodash/issues/3359[WEB]
- https://github.com/github/advisory-database/pull/6138[WEB]
- https://github.com/lodash/lodash/commit/5c08f18d365b64063bfbfa686cbb97cdd6267347[WEB]
- https://github.com/lodash/lodash[PACKAGE]
- https://github.com/lodash/lodash/wiki/Changelog[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-1010266.yml[WEB]
- https://security.netapp.com/advisory/ntap-20190919-0004[WEB]
- https://snyk.io/vuln/SNYK-JS-LODASH-73639[WEB]