Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-8p5q-j9m2-g8wr] Withdrawn: Arbitrary code execution in lodash #5010

Conversation

t-vorobyova
Copy link

Updates

  • Affected products
  • References
  • Severity

Comments
It doesn't match with https://nvd.nist.gov/vuln/detail/CVE-2021-23337
https://nvd.nist.gov/vuln/detail/CVE-2021-41720 was rejected

@github-actions github-actions bot changed the base branch from main to t-vorobyova/advisory-improvement-5010 November 15, 2024 08:57
@darakian
Copy link
Contributor

Not sure I follow you here @t-vorobyova. Could you clarify your goal with this PR please?

@t-vorobyova
Copy link
Author

@darakian GHSA-8p5q-j9m2-g8wr has 4.17.21 in affected versions, but it doesn't match with https://nvd.nist.gov/vuln/detail/CVE-2021-23337.
And I also want to delete link to https://nvd.nist.gov/vuln/detail/CVE-2021-41720 because it was rejected

@darakian
Copy link
Contributor

This advisory has been withdrawn on our end. There are no alerts being generated from it, but we maintain the state of the advisory as a historical reference.

@darakian darakian closed this Nov 19, 2024
@github-actions github-actions bot deleted the t-vorobyova-GHSA-8p5q-j9m2-g8wr branch November 19, 2024 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants