You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Summary:
lodash package, versions inferior to 4.17.20 are vulnerable to Prototype Pollution in zipObjectDeep due to an incomplete fix for CVE-2020-8203
Severity:
Medium
Priority:
High
Expected Behavior
Upgrade lodash to version 4.17.20 or higher.
Steps to Reproduce
N/A
Specifications
Component (if known):
Version: Related to lodash package, versions <4.17.20.
Platform: Mowali
Subsystem:
Type of testing:
Bug found/raised by: Mowali
Notes:
Severity when opened:
Priority when opened:
The text was updated successfully, but these errors were encountered:
Dorota-MB
added
the
bug
Something isn't working or it has wrong behavior on a Mojaloop Core service
label
May 10, 2021
elnyry-sam-k
added
story
oss-core
This is an issue - story or epic related to a feature on a Mojaloop core service or related to it
and removed
bug
Something isn't working or it has wrong behavior on a Mojaloop Core service
labels
May 10, 2021
Summary:
lodash package, versions inferior to 4.17.20 are vulnerable to Prototype Pollution in zipObjectDeep due to an incomplete fix for CVE-2020-8203
Severity:
Medium
Priority:
High
Expected Behavior
Upgrade lodash to version 4.17.20 or higher.
Steps to Reproduce
N/A
Specifications
Notes:
The text was updated successfully, but these errors were encountered: