[GHSA-29mw-wpgm-hmr9] Regular Expression Denial of Service (ReDoS) in lodash#6139
Conversation
|
Hi @levpachmanov, we are in the process of reviewing this information and will follow up when we have more on the matter. This applies to #6138 as well. Thank you for your patience! |
|
Hi @helixplant, anything I can do to help get this one and #6318 processed? |
|
Hi @levpachmanov, |
d8edc60
into
levpachmanov/advisory-improvement-6139
|
Hi @levpachmanov! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
github/advisory-database#6139 placed a lower bound on a couple of advisories related to NPM packages which causes some TP labels to be FPs for older versions of the packages. Signed-off-by: Weston Steimel <author@code.w.steimel.me.uk>
github/advisory-database#6139 placed a lower bound on a couple of advisories related to NPM packages which causes some TP labels to be FPs for older versions of the packages. Signed-off-by: Weston Steimel <author@code.w.steimel.me.uk>
Updates
Comments
I took the unittest which were added in lodash/lodash@c4847eb, wrote them as a single file, and ran on 3.10.1 and 4.0.0:
output for 3.10.1:
output for 4.0.0: