Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE in dependency lodash.set #36

Open
AnWeber opened this issue Jan 26, 2024 · 0 comments · May be fixed by #38
Open

CVE in dependency lodash.set #36

AnWeber opened this issue Jan 26, 2024 · 0 comments · May be fixed by #38

Comments

@AnWeber
Copy link

AnWeber commented Jan 26, 2024

Thank you for your package. I have included it my projekt httpyac, but now I also get npm audit errors. There is a CVE in lodash.set. Could you possibly switch to an alternative like lodash or lodash-es to fix this?

see GHSA-p6mc-m468-83gw

lodash.set  *
Severity: high
Prototype Pollution in lodash - https://github.com/advisories/GHSA-p6mc-m468-83gw
No fix available
node_modules/lodash.set
  grpc-reflection-js  *
  Depends on vulnerable versions of lodash.set
  node_modules/grpc-reflection-js

2 high severity vulnerabilities
@jackkav jackkav linked a pull request Aug 3, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant