noodlefrenzy / node-amqp10

amqp10 is a promise-based, AMQP 1.0 compliant node.js client
MIT License
134 stars 56 forks source link

Security Vulnerability with lodash@4.17.20 #376

Open skvijay007 opened 3 years ago

skvijay007 commented 3 years ago

This latest version of lodash has security vulnerability of Command Injection (CVE-2021-23337).

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23337

https://snyk.io/vuln/SNYK-JS-LODASH-1040724

All versions of package lodash; all versions of package org.fujion.webjars:lodash are vulnerable to Command Injection via template.