Skip to content

lodash.set vulnerability #99

@mhoffman39

Description

@mhoffman39

I'm using version 0.0.6 (most current) and getting this high severity vulnerability.

lodash.set *
Severity: high
Prototype Pollution in lodash - GHSA-p6mc-m468-83gw
No fix available
node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set
@aws-amplify/cdk-exported-backend *
Depends on vulnerable versions of lodash.set
Depends on vulnerable versions of uuid
node_modules/@aws-amplify/cdk-exported-backend

I see that this vulnerability has been fixed but the release hasn't been released. Is there a plan to release this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions