Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in old version of lodash #2528

Open
jmattstevens opened this issue Apr 24, 2024 · 3 comments
Open

Security vulnerability in old version of lodash #2528

jmattstevens opened this issue Apr 24, 2024 · 3 comments

Comments

@jmattstevens
Copy link

Describe the bug
The redoc/benchmark/index.html file references an obsolete version of lodash (4.17.4) with a known vulnerability that was fixed in later versions. The latest version is 4.17.21, which seems to have fixed the problem. Could the vulnerable version be replaced with the fixed version? Is the benchmark folder necessary to run redoc?

Expected behavior
I expected redoc to pass muster with the security team at my company, but it was rejected because of the known vulnerability. See attached file.
Redoc ML-vulnerability-report.xlsx

Minimal reproducible OpenAPI snippet(if possible)

Screenshots
If applicable, add screenshots to help explain your problem.

Additional context
Add any other context about the problem here.

@AlexVarchuk
Copy link
Collaborator

we do not include redoc/benchmark/index.html to lib code. Later we'll fix that

@jmattstevens
Copy link
Author

jmattstevens commented Apr 25, 2024 via email

@AlexVarchuk
Copy link
Collaborator

yes, you can check it in file list. For example on npm/redoc

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants