debricked / soot-wrapper

Analyses how you use your dependencies to figure out if you use the vulnerable parts of a vulnerable dependency
MIT License
4 stars 5 forks source link

A new vulnerability was discovered: CVE-2018-20225 #6

Closed debricked[bot] closed 2 years ago

debricked[bot] commented 3 years ago

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.

Read more at Debricked: https://app.debricked.com/en/service/vulnerability/126061