Skip to content

Usage of a vulnerable package #4490

@guy-microsoft

Description

@guy-microsoft

The botbuilder-dialogs v4.19.3 package depends on @microsoft/recognizers-text-number which uses lodash.trimend v4.5.1 that includes this vulnerability:
https://nvd.nist.gov/vuln/detail/cve-2020-28500

Metadata

Metadata

Assignees

Labels

bugIndicates an unexpected problem or an unintended behavior.needs-triageThe issue has just been created and it has not been reviewed by the team.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions