[wp-trac] [WordPress Trac] #49732: lodash 4.17.15 The lodash package is vulnerable to Prototype Pollution.

WordPress Trac noreply at wordpress.org
Tue Mar 31 03:45:04 UTC 2020


#49732: lodash 4.17.15 The lodash package is vulnerable to Prototype Pollution.
--------------------------+------------------------------
 Reporter:  tlterry       |       Owner:  (none)
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  General       |     Version:
 Severity:  critical      |  Resolution:
 Keywords:                |     Focuses:
--------------------------+------------------------------

Comment (by tlterry):

 Both related files located at file path below.

 **lodash.js** located at /wp-includes/js/dist/vendor
 **lodash.min.js** located at /wp-includes/js/dist/vendor

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/49732#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list