Redux version 0.6.2 represents a minor but notable update to this popular state management library, building upon the foundation laid by version 0.6.1. Both versions, created by Dan Abramov, are described as experiments in fully hot-reloadable Flux architecture, highlighting the library's emphasis on developer experience and efficient workflow. Key dependencies remain consistent between the two, including Babel runtime, Envify, Invariant, Lodash, and React, ensuring compatibility and expected functionality for users already familiar with the 0.6.1 ecosystem. The core development dependencies, encompassing tools like Babel, ESLint, React Hot Loader, and Webpack, also remain unchanged, suggesting a focus on stability and refinement rather than a major overhaul of the development process.
The most significant differentiator between versions 0.6.1 and 0.6.2 lies in their release dates. Version 0.6.2 was published just a few minutes after 0.6.1 (2015-06-04T14:02:11.291Z vs 2015-06-04T13:42:40.279Z), indicating a very quick patch or minor adjustment between the two. While the explicit nature of the changes isn't detailed in the metadata, developers should likely consider 0.6.2 the preferred version due to its more recent publication. Given the minimal time difference, it likely addresses a bug fix or a very small enhancement identified immediately after the initial 0.6.1 release. Users adopting Redux during this early phase would benefit from using the newer version to ensure they're leveraging the most up-to-date, potentially more stable iteration of the library. Both versions are licensed under MIT, and the primary repository is accessible on Github.
All the vulnerabilities related to the version 0.6.2 of the package
Prototype Pollution in lodash
Versions of lodash
before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep
allows a malicious user to modify the prototype of Object
via {constructor: {prototype: {...}}}
causing the addition or modification of an existing property that will exist on all objects.
Update to version 4.17.12 or later.
Prototype Pollution in lodash
Versions of lodash
before 4.17.5 are vulnerable to prototype pollution.
The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of Object
via __proto__
causing the addition or modification of an existing property that will exist on all objects.
Update to version 4.17.5 or later.
Prototype Pollution in lodash
Versions of lodash
before 4.17.11 are vulnerable to prototype pollution.
The vulnerable functions are 'defaultsDeep', 'merge', and 'mergeWith' which allow a malicious user to modify the prototype of Object
via {constructor: {prototype: {...}}}
causing the addition or modification of an existing property that will exist on all objects.
Update to version 4.17.11 or later.
Regular Expression Denial of Service (ReDoS) in lodash
lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.
Prototype Pollution in lodash
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions pick
, set
, setWith
, update
, updateWith
, and zipObjectDeep
allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays.
This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
Regular Expression Denial of Service (ReDoS) in lodash
All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber
, trim
and trimEnd
functions.
Steps to reproduce (provided by reporter Liyuan Chen):
var lo = require('lodash');
function build_blank(n) {
var ret = "1"
for (var i = 0; i < n; i++) {
ret += " "
}
return ret + "1";
}
var s = build_blank(50000) var time0 = Date.now();
lo.trim(s)
var time_cost0 = Date.now() - time0;
console.log("time_cost0: " + time_cost0);
var time1 = Date.now();
lo.toNumber(s) var time_cost1 = Date.now() - time1;
console.log("time_cost1: " + time_cost1);
var time2 = Date.now();
lo.trimEnd(s);
var time_cost2 = Date.now() - time2;
console.log("time_cost2: " + time_cost2);
Command Injection in lodash
lodash
versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Cross-Site Scripting in react
Versions of react
prior to 0.14.0 are vulnerable to Cross-Site Scripting (XSS). The package's createElement
function fails to properly validate its input object, allowing attackers to execute arbitrary JavaScript in a victim's browser.
Upgrade to version 0.14.0 or later.