apk package
chainguard/wazuh-dashboard-dashboards-reporting
pkg:apk/chainguard/wazuh-dashboard-dashboards-reporting
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-13465 | Med | 5.3 | < 4.14.7-r9 | 4.14.7-r9 | Jan 21, 2026 | Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritin | |
| CVE-2024-1899 | Med | 5.3 | < 4.14.7-r10 | 4.14.7-r10 | Feb 26, 2024 | An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions. |
- affected < 4.14.7-r9fixed 4.14.7-r9
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritin
- affected < 4.14.7-r10fixed 4.14.7-r10
An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.
Page 3 of 3