{"source":1096995,"name":"lodash-es","dependency":"lodash-es","title":"Command Injection in lodash","url":"https://github.com/advisories/GHSA-35jh-r3h4-6jhm","severity":"high","versions":["3.0.0","3.0.1","3.1.0","3.2.0","3.3.0","3.3.1","3.4.0","3.5.0","3.6.0","3.7.0","3.8.0","3.9.0","3.9.2","3.9.3","3.10.0","3.10.1","4.0.0","4.0.1","4.1.0","4.2.0","4.2.1","4.3.0","4.4.0","4.5.0","4.5.1","4.6.0","4.6.1","4.7.0","4.8.0","4.8.2","4.9.0","4.10.0","4.11.0","4.11.1","4.11.2","4.12.0","4.13.0","4.13.1","4.14.0","4.14.1","4.14.2","4.15.0","4.16.0","4.16.1","4.16.2","4.16.3","4.16.4","4.16.5","4.16.6","4.17.0","4.17.1","4.17.2","4.17.3","4.17.4","4.17.5","4.17.6","4.17.7","4.17.8","4.17.9","4.17.10","4.17.11","4.17.12","4.17.13","4.17.14","4.17.15","4.17.20","4.17.21"],"vulnerableVersions":["3.0.0","3.0.1","3.1.0","3.2.0","3.3.0","3.3.1","3.4.0","3.5.0","3.6.0","3.7.0","3.8.0","3.9.0","3.9.2","3.9.3","3.10.0","3.10.1","4.0.0","4.0.1","4.1.0","4.2.0","4.2.1","4.3.0","4.4.0","4.5.0","4.5.1","4.6.0","4.6.1","4.7.0","4.8.0","4.8.2","4.9.0","4.10.0","4.11.0","4.11.1","4.11.2","4.12.0","4.13.0","4.13.1","4.14.0","4.14.1","4.14.2","4.15.0","4.16.0","4.16.1","4.16.2","4.16.3","4.16.4","4.16.5","4.16.6","4.17.0","4.17.1","4.17.2","4.17.3","4.17.4","4.17.5","4.17.6","4.17.7","4.17.8","4.17.9","4.17.10","4.17.11","4.17.12","4.17.13","4.17.14","4.17.15","4.17.20"],"cwe":["CWE-77","CWE-94"],"cvss":{"score":7.2,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"range":"<4.17.21","id":"GQy/XWSgzmSZaFDDJZe+4WrE9xai5qRn+7CUXTwbA/w80qovHBt4cQ7xcexu6Sz27E0iPgTBtlZn+YczeWupKQ=="}