Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-1010266

Description

lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.

POC

Reference

- https://snyk.io/vuln/SNYK-JS-LODASH-73639

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/HotDB-Community/HotDB-Engine

- https://github.com/chkp-dhouari/CloudGuard-ShiftLeft-CICD

- https://github.com/dcambronero/shiftleft

- https://github.com/endorama/CsvToL10nJson

- https://github.com/najla-zwawi/SpectrolOpsTest

- https://github.com/nilsujma-dev/CloudGuard-ShiftLeft-CICD

- https://github.com/ossf-cve-benchmark/CVE-2019-1010266

- https://github.com/p3sky/Cloudguard-Shifleft-CICD

- https://github.com/puryersc/shiftleftv2

- https://github.com/puryersc/shiftleftv3

- https://github.com/puryersc/shiftleftv4

- https://github.com/seal-community/patches