Skip to content

Commit 31f3c77

Browse files
karanh37claude
andcommitted
Fix lodash prototype pollution vulnerability (CVE)
Bump lodash from 4.17.21 to 4.17.23 to patch prototype pollution in _.unset and _.omit. Add yarn resolution to force all transitive dependents to use the patched version. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
1 parent 0422260 commit 31f3c77

File tree

2 files changed

+7
-6
lines changed

2 files changed

+7
-6
lines changed

openmetadata-ui/src/main/resources/ui/package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -108,7 +108,7 @@
108108
"js-yaml": "^4.1.1",
109109
"jwt-decode": "^3.1.2",
110110
"katex": "^0.16.21",
111-
"lodash": "^4.17.21",
111+
"lodash": "^4.17.23",
112112
"luxon": "^3.2.1",
113113
"notistack": "^3.0.2",
114114
"oidc-client": "^1.11.5",
@@ -262,6 +262,7 @@
262262
"on-headers": "1.1.0",
263263
"form-data": "3.0.4",
264264
"tar-fs": "2.1.4",
265-
"js-yaml": "4.1.1"
265+
"js-yaml": "4.1.1",
266+
"lodash": ">=4.17.23"
266267
}
267268
}

openmetadata-ui/src/main/resources/ui/yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9386,10 +9386,10 @@ lodash.throttle@^4.1.1:
93869386
resolved "https://registry.npmjs.org/lodash.throttle/-/lodash.throttle-4.1.1.tgz"
93879387
integrity sha512-wIkUCfVKpVsWo3JSZlc+8MB5it+2AN5W8J7YVMST30UrvcQNZ1Okbj+rbVniijTWE6FGYy4XJq/rHkas8qJMLQ==
93889388

9389-
lodash@>=4.17.21, lodash@^4.15.0, lodash@^4.17.15, lodash@^4.17.19, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.4:
9390-
version "4.17.21"
9391-
resolved "https://registry.npmjs.org/lodash/-/lodash-4.17.21.tgz"
9392-
integrity sha512-v2kDEe57lecTulaDIuNTPy3Ry4gLGJ6Z1O3vE1krgXZNrsQ+LFTGHVxVjcXPs17LhbZVGedAJv8XZ1tvj5FvSg==
9389+
lodash@>=4.17.21, lodash@>=4.17.23, lodash@^4.15.0, lodash@^4.17.15, lodash@^4.17.19, lodash@^4.17.20, lodash@^4.17.21, lodash@^4.17.23, lodash@^4.17.4:
9390+
version "4.17.23"
9391+
resolved "https://registry.yarnpkg.com/lodash/-/lodash-4.17.23.tgz#f113b0378386103be4f6893388c73d0bde7f2c5a"
9392+
integrity sha512-LgVTMpQtIopCi79SJeDiP0TfWi5CNEc/L/aRdTh3yIvmZXTnheWpKjSZhnvMl8iXbC1tFg9gdHHDMLoV7CnG+w==
93939393

93949394
log-symbols@^4.0.0:
93959395
version "4.1.0"

0 commit comments

Comments
 (0)