Title: CVE-2020-28500 (Medium) detected in lodash-4.17.15.tgz · Issue #3 · KDWSS/api-extractor-example · GitHub
Open Graph Title: CVE-2020-28500 (Medium) detected in lodash-4.17.15.tgz · Issue #3 · KDWSS/api-extractor-example
X Title: CVE-2020-28500 (Medium) detected in lodash-4.17.15.tgz · Issue #3 · KDWSS/api-extractor-example
Description: CVE-2020-28500 - Medium Severity Vulnerability Vulnerable Library - lodash-4.17.15.tgz Lodash modular utilities. Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz Path to dependency file: /package.json Path to vul...
Open Graph Description: CVE-2020-28500 - Medium Severity Vulnerability Vulnerable Library - lodash-4.17.15.tgz Lodash modular utilities. Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz Path to de...
X Description: CVE-2020-28500 - Medium Severity Vulnerability Vulnerable Library - lodash-4.17.15.tgz Lodash modular utilities. Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz Path to de...
Opengraph URL: https://github.com/KDWSS/api-extractor-example/issues/3
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"CVE-2020-28500 (Medium) detected in lodash-4.17.15.tgz","articleBody":"## CVE-2020-28500 - Medium Severity Vulnerability\n\u003cdetails\u003e\u003csummary\u003e\u003cimg src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20\u003e Vulnerable Library - \u003cb\u003elodash-4.17.15.tgz\u003c/b\u003e\u003c/p\u003e\u003c/summary\u003e\n\n\u003cp\u003eLodash modular utilities.\u003c/p\u003e\n\u003cp\u003eLibrary home page: \u003ca href=\"https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz\"\u003ehttps://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003ePath to dependency file: /package.json\u003c/p\u003e\n\u003cp\u003ePath to vulnerable library: /node_modules/lodash/package.json\u003c/p\u003e\n\u003cp\u003e\n\nDependency Hierarchy:\n - api-extractor-7.0.17.tgz (Root Library)\n - :x: **lodash-4.17.15.tgz** (Vulnerable Library)\n\u003cp\u003eFound in HEAD commit: \u003ca href=\"https://github.com/KDWSS/api-extractor-example/commit/4585931fac1a45c9a7aca3c8ff03d936f849539b\"\u003e4585931fac1a45c9a7aca3c8ff03d936f849539b\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eFound in base branch: \u003cb\u003emaster\u003c/b\u003e\u003c/p\u003e\n\u003c/p\u003e\n\u003c/details\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cdetails\u003e\u003csummary\u003e\u003cimg src='https://whitesource-resources.whitesourcesoftware.com/medium_vul.png' width=19 height=20\u003e Vulnerability Details\u003c/summary\u003e\n\u003cp\u003e \n \nLodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.\n WhiteSource Note: After conducting further research, WhiteSource has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash.\n\n\u003cp\u003ePublish Date: 2021-02-15\n\u003cp\u003eURL: \u003ca href=https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-28500\u003eCVE-2020-28500\u003c/a\u003e\u003c/p\u003e\n\u003c/p\u003e\n\u003c/details\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cdetails\u003e\u003csummary\u003e\u003cimg src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20\u003e CVSS 3 Score Details (\u003cb\u003e5.3\u003c/b\u003e)\u003c/summary\u003e\n\u003cp\u003e\n\nBase Score Metrics:\n- Exploitability Metrics:\n - Attack Vector: Network\n - Attack Complexity: Low\n - Privileges Required: None\n - User Interaction: None\n - Scope: Unchanged\n- Impact Metrics:\n - Confidentiality Impact: None\n - Integrity Impact: None\n - Availability Impact: Low\n\u003c/p\u003e\nFor more information on CVSS3 Scores, click \u003ca href=\"https://www.first.org/cvss/calculator/3.0\"\u003ehere\u003c/a\u003e.\n\u003c/p\u003e\n\u003c/details\u003e\n\u003cp\u003e\u003c/p\u003e\n\u003cdetails\u003e\u003csummary\u003e\u003cimg src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20\u003e Suggested Fix\u003c/summary\u003e\n\u003cp\u003e\n\n\u003cp\u003eType: Upgrade version\u003c/p\u003e\n\u003cp\u003eOrigin: \u003ca href=\"https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500\"\u003ehttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRelease Date: 2021-02-15\u003c/p\u003e\n\u003cp\u003eFix Resolution (lodash): 4.17.21\u003c/p\u003e\n\u003cp\u003eDirect dependency fix Resolution (@microsoft/api-extractor): 7.0.18\u003c/p\u003e\n\n\u003c/p\u003e\n\u003c/details\u003e\n\u003cp\u003e\u003c/p\u003e\n\n***\n:rescue_worker_helmet: Automatic Remediation is available for this issue\n\u003c!-- \u003cREMEDIATE\u003e{\"isOpenPROnVulnerability\":true,\"isPackageBased\":true,\"isDefaultBranch\":true,\"packages\":[{\"packageType\":\"javascript/Node.js\",\"packageName\":\"@microsoft/api-extractor\",\"packageVersion\":\"7.0.17\",\"packageFilePaths\":[\"/package.json\"],\"isTransitiveDependency\":false,\"dependencyTree\":\"@microsoft/api-extractor:7.0.17\",\"isMinimumFixVersionAvailable\":true,\"minimumFixVersion\":\"7.0.18\",\"isBinary\":false}],\"baseBranches\":[\"master\"],\"vulnerabilityIdentifier\":\"CVE-2020-28500\",\"vulnerabilityDetails\":\"Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.\\n WhiteSource Note: After conducting further research, WhiteSource has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash.\",\"vulnerabilityUrl\":\"https://vuln.whitesourcesoftware.com/vulnerability/CVE-2020-28500\",\"cvss3Severity\":\"medium\",\"cvss3Score\":\"5.3\",\"cvss3Metrics\":{\"A\":\"Low\",\"AC\":\"Low\",\"PR\":\"None\",\"S\":\"Unchanged\",\"C\":\"None\",\"UI\":\"None\",\"AV\":\"Network\",\"I\":\"None\"},\"extraData\":{}}\u003c/REMEDIATE\u003e --\u003e","author":{"url":"https://github.com/mend-for-github-com[bot]","@type":"Person","name":"mend-for-github-com[bot]"},"datePublished":"2021-11-01T15:35:54.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/3/api-extractor-example/issues/3"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:73488b9a-4486-4229-05af-a6be0b40e945 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | E35C:20DA71:48AF6CF:6047BD9:6A5D8BC9 |
| html-safe-nonce | 292ae6c93a044243d93defb66f8ed42334c2aa549bb3efb523c1ad9c4df30e7d |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJFMzVDOjIwREE3MTo0OEFGNkNGOjYwNDdCRDk6NkE1RDhCQzkiLCJ2aXNpdG9yX2lkIjoiMTk2NTkzNjQ4NTk4OTE5MDYwMSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | da54e5c67ff23de72a1fdb4aa03e27c71c572a5643fd4649312c9968c9a59b8d |
| hovercard-subject-tag | issue:1041307864 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/KDWSS/api-extractor-example/3/issue_layout |
| twitter:image | https://opengraph.githubassets.com/99c8bee4f407fe7e17e406655cdd261bdf16cbc615509e36a77b66c23823d7c9/KDWSS/api-extractor-example/issues/3 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/99c8bee4f407fe7e17e406655cdd261bdf16cbc615509e36a77b66c23823d7c9/KDWSS/api-extractor-example/issues/3 |
| og:image:alt | CVE-2020-28500 - Medium Severity Vulnerability Vulnerable Library - lodash-4.17.15.tgz Lodash modular utilities. Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.15.tgz Path to de... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | mend-for-github-com[bot] |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5290d7e14309ad1e76106a9c4237bd1041517e83ea182c8ab756752cb0c6940b |
| turbo-cache-control | no-preview |
| go-import | github.com/KDWSS/api-extractor-example git https://github.com/KDWSS/api-extractor-example.git |
| octolytics-dimension-user_id | 88722482 |
| octolytics-dimension-user_login | KDWSS |
| octolytics-dimension-repository_id | 423518906 |
| octolytics-dimension-repository_nwo | KDWSS/api-extractor-example |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 423518906 |
| octolytics-dimension-repository_network_root_nwo | KDWSS/api-extractor-example |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 9c975978430e9ad293956f2bbdaf153b1bd84a99 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width