Project

General

Profile

Actions

Bug #39081

closed

lodash: Bump from 4.17.21 to 4.17.23 due to CVE-2025-13465

Added by Maximilian Kolb 6 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Normal
Category:
RPMs
Target version:
-
Difficulty:
Triaged:
No

Description

Various RPMs in foreman-packaging reference lodash in a version that is affected by a CVE. As of now, only the source of "nodejs-lodash" has been fixed.

Refs https://www.cve.org/CVERecord?id=CVE-2025-13465
Refs https://github.com/theforeman/foreman-packaging/pull/12939

Actions

Also available in: Atom PDF