-
Type: Bug
-
Status: Open
-
Priority: Minor
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Web UI
-
Tags:
-
Sprint:UI - 2024-12
SRCCLR-SID-25849 | Unknown
Severity : Medium
lodash is vulnerable to injection vulnerability. An attacker can inject malicious code via `sourceURL` since it is not sanitized for the userprovided code that leads to the `eval()` function.
Module : loadash
nuxeo-web-ui.zip#zip:packages/nuxeo-designer-catalog/node_modules:lodash
Current Version : 3.10.1
Recommended Upgrade Version : 4.17.21