You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detailed paths
Introduced through: fec-cms@1.0.0 › underscore@1.9.1
Remediation: Upgrade to underscore@1.12.1
Introduced through: fec-cms@1.0.0 › glossary-panel@1.0.0 › underscore@1.9.1
Remediation: No remediation path available.
Overview
underscore is a JavaScript's functional programming helper library.
Affected versions of this package are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Completion criteria
Determine how we're affected by this
Decide whether we tag this to come back when there's a remediation path, OR refactor all of our codebase to remove underscore (and/or lodash)
The text was updated successfully, but these errors were encountered:
This upgrade broke our filings datatables on the canonical candidate and committee profile pages. Need to revisit to see how to upgrade and patch this later.
Summary
Underscore Arbitrary Code Execution
Detailed paths
Introduced through: fec-cms@1.0.0 › underscore@1.9.1
Remediation: Upgrade to underscore@1.12.1
Introduced through: fec-cms@1.0.0 › glossary-panel@1.0.0 › underscore@1.9.1
Remediation: No remediation path available.
Overview
underscore is a JavaScript's functional programming helper library.
Affected versions of this package are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Completion criteria
The text was updated successfully, but these errors were encountered: