Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: lodash: 4.17.21 identified as vulnerable multiple cve's #6414

Open
proo4509 opened this issue Jan 22, 2024 · 4 comments
Open

[FP]: lodash: 4.17.21 identified as vulnerable multiple cve's #6414

proo4509 opened this issue Jan 22, 2024 · 4 comments

Comments

@proo4509
Copy link

Package URl

https://ossindex.sonatype.org/component/pkg:npm/lodash@0px

CPE

pkg:javascript/lodash@0px

CVE

CVE-2019-10744 CVE-2021-23337 CVE-2018-3721 CVE-2019-1010266 CVE-2018-16487 CVE-2020-28500

ODC Integration

{"label"=>"CLI"}

ODC Version

9.0.9

Description

Versions of lodash lower than 4.17.12 have the following cve's:
CVE-2019-10744
CVE-2021-23337
CVE-2018-3721
CVE-2019-1010266
CVE-2018-16487
CVE-2020-28500

But they are also flagged for lodash: 4.17.21

Copy link
Contributor

Error parsing package url: https://ossindex.sonatype.org/component/pkg:npm/lodash@0px.

Error: Error: purl is missing the required "pkg" scheme component.

Please correct the package URL - consider copying the package url from the HTML report.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/7612404195

@aikebah
Copy link
Collaborator

aikebah commented Apr 13, 2024

I tried the following:

  1. Start in an empty repository
  2. Run npm i [email protected]
  3. Run /path/to/dependencycheck/bin/dependency-check.sh -s .

But fail to reproduce. Based on the URL towards OSSIndex that you quote you suffer from a mangled lodash package that gets identified as lodash version 0px.

My run properly shows lodash as lodash v4.17.21 and surfaces no FPs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants