QID 377842
Date Published: 2022-12-20
QID 377842: Lodash Command Injection Vulnerability
Lodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.
Affected Version
lodash prior to 4.17.21
QID Detection Logic
It checks for the vulnerable version of lodash using npm list command
An attacker can exploit the system via Command Injection via the template function.
Solution
Customers are advised to update to the patched version of lodash modules lodash v4.17.21
Vendor References
- GHSA-35jh-r3h4-6jhm -
github.com/advisories/GHSA-35jh-r3h4-6jhm
CVEs related to QID 377842
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-23337 |
|