nerror icon indicating copy to clipboard operation
nerror copied to clipboard

Prototype Pollution in lodash versions <=4.7.11

Open VinodhiniV opened this issue 6 years ago • 1 comments

image

As there s a vulnerability in the lodash version used by Netflix/nerror, could you please help us by updating to latest version of lodash.

We are blocked due to this vulnerability in lodash version.

Thanks

VinodhiniV avatar Jul 25 '19 17:07 VinodhiniV

Actually, the lodash version used here is ^4.17.15, which means 4.17.x. This way this range reaches the current latest version of lodash. Probably, your lock file is outdated, try to update your lock file.

This issue should be closed.

richardaum avatar Aug 03 '23 00:08 richardaum