CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | 7.2 |
High |
||
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | 5.3 |
Medium |
||
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | 7.4 |
High |