Skip to content

[GHSA-4xc9-xhrj-v574] Prototype Pollution in lodash #5980

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

G-Rath
Copy link

@G-Rath G-Rath commented Aug 10, 2025

Updates

  • Affected products

Comments
Added lodash-rails to list of impacted packages

@Copilot Copilot AI review requested due to automatic review settings August 10, 2025 19:24
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a GitHub Security Advisory (GHSA-4xc9-xhrj-v574) for a prototype pollution vulnerability in lodash by adding lodash-rails to the list of affected packages.

  • Adds lodash-rails RubyGems package to the affected products list
  • Updates the modification timestamp to reflect the change

"introduced": "0"
},
{
"fixed": "4.17.11"
Copy link
Preview

Copilot AI Aug 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fixed version "4.17.11" appears to be a lodash (JavaScript) version number, but this entry is for the "lodash-rails" RubyGems package which likely has different versioning. Please verify the correct fixed version for the lodash-rails gem.

Copilot uses AI. Check for mistakes.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is the correct version - the gems versioning matches the version of lodash that it provides (at least in the 4.x line)

@github-actions github-actions bot changed the base branch from main to G-Rath/advisory-improvement-5980 August 10, 2025 19:25
@advisory-database advisory-database bot merged commit 7b8bdc9 into G-Rath/advisory-improvement-5980 Aug 11, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @G-Rath! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the G-Rath-GHSA-4xc9-xhrj-v574 branch August 11, 2025 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant