[ 
https://issues.apache.org/jira/browse/HBASE-29848?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18053843#comment-18053843
 ] 

Dávid Paksy commented on HBASE-29848:
-------------------------------------

Thanks for the review [~yurii]. I merged the PR to master.

> Bump lodash from 4.17.21 to 4.17.23 in /hbase-website
> -----------------------------------------------------
>
>                 Key: HBASE-29848
>                 URL: https://issues.apache.org/jira/browse/HBASE-29848
>             Project: HBase
>          Issue Type: Task
>          Components: website
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>
> New moderate CVE:
> Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` 
> functions
> [https://github.com/apache/hbase/security/dependabot/125]
> Transitive dependency *lodash 4.17.21* is introduced via
>  * @react-router/dev 7.12.0  lodash 4.17.21



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to