lodash CVE
-
I recently got a report from my orgs IT team that a couple CVEs were identified in versions of lodash <4.17.21.
To meet our orgs compliance deadline I had to manually upgrade this plugins lodash script to v4.17.21, in addition to other lodash copies in WordPress core and a other plugins I am using, just saw y’all released an update for 1.14.1 and I expect updating to that version will revert my local change.Additionally, in digging around a bit, WordPress core as of 6.2.2 includes lodash 4.17.21 which you could enqueue instead of registering your own copy and avoid the maintenance overhead.
sauce: https://wordpress.org/support/topic/lodash-vulnerabilities/#post-16936369
The CVEs in question are:
Reachable and EPSS > 1%- HIGH: CVE-2020-8203
Reachable and EPSS < 1%
- HIGH: CVE-2021-23337
- MEDIUM: [CVE-2020-28500|N/A]
The topic ‘lodash CVE’ is closed to new replies.