Bug 2432993
| Summary: | CVE-2025-13465 qt6-qtbase: prototype pollution in _.unset and _.omit functions [fedora-42] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | qt6-qtbase | Assignee: | Jan Grulich <jgrulich> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 42 | CC: | jgrulich, kde-sig |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["2207a801-158d-4213-ada5-49f943885c4d"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-01-27 09:27:30 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2431740 | ||
|
Description
Guilherme de Almeida Suckevicz
2026-01-26 18:46:14 UTC
Lodash is used in a tool that is only used by the Qt developers to generate presets that are included in Qt, but the tool it not build and Lodash is not even part of the Qt source code. |