Skip to content

lodash.set vulnerability #99

Description

@mhoffman39

I'm using version 0.0.6 (most current) and getting this high severity vulnerability.

lodash.set *
Severity: high
Prototype Pollution in lodash - GHSA-p6mc-m468-83gw
No fix available
node_modules/@aws-amplify/cdk-exported-backend/node_modules/lodash.set
@aws-amplify/cdk-exported-backend *
Depends on vulnerable versions of lodash.set
Depends on vulnerable versions of uuid
node_modules/@aws-amplify/cdk-exported-backend

I see that this vulnerability has been fixed but the release hasn't been released. Is there a plan to release this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions