lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| lodash(npm) | 4.7.0 | 4.17.11 | N/A |
| lodash-es(npm) | 4.7.0 | 4.17.11 | N/A |
| lodash-amd(npm) | 4.7.0 | 4.17.11 | N/A |
| lodash-rails(RubyGems) | 4.7.0 | 4.17.11 | N/A |
CVSS Metrics