Arbitrary Command Injection The advisory has been revoked - it doesn't affect any version of package node-lodash Open this link in a new tab
Threat Intelligence
EPSS
0.15% (51st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN10-NODELODASH-1727527
- published 2 Oct 2021
- disclosed 30 Sep 2021
Introduced: 30 Sep 2021
CVE-2021-41720 Open this link in a new tabAmendment
The Debian
security team deemed this advisory irrelevant for Debian:10
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream node-lodash
package and not the node-lodash
package as distributed by Debian
.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none