Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| lodash(npm) | 4.0.0 | 4.17.21 | N/A |
| lodash-es(npm) | 4.0.0 | 4.17.21 | N/A |
| lodash.trimend(npm) | 4.0.0 | N/A | N/A |
| lodash.trim(npm) | 4.0.0 | N/A | N/A |
| lodash-rails(RubyGems) | 4.0.0 | 4.17.21 | N/A |
CVSS Metrics