Project

General

Profile

Actions

Bug #39081

closed

lodash: Bump from 4.17.21 to 4.17.23 due to CVE-2025-13465

Added by Maximilian Kolb 5 months ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Category:
RPMs
Target version:
-
Difficulty:
Triaged:
No

Description

Various RPMs in foreman-packaging reference lodash in a version that is affected by a CVE. As of now, only the source of "nodejs-lodash" has been fixed.

Refs https://www.cve.org/CVERecord?id=CVE-2025-13465
Refs https://github.com/theforeman/foreman-packaging/pull/12939

Actions #1

Updated by The Foreman Bot 5 months ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman-packaging/pull/13038 added
Actions #2

Updated by The Foreman Bot 4 months ago

  • Pull request deleted (https://github.com/theforeman/foreman-packaging/pull/13038)
Actions #3

Updated by Evgeni Golov 4 months ago

  • Status changed from Ready For Testing to Closed
  • Fixed in Releases 3.19.0 added
Actions

Also available in: Atom PDF