Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
_.unset and _.omit are never called anywhere: not in the cockpit-389-ds source code, not in @patternfly, and not in victory-* packages. Even if the vulnerable functions were called, exploitation requires an attacker to control the path argument. cockpit-389-ds is an application for Cockpit admin console, it runs locally, not as a public-facing web service. And no lodash path-based functions receive user-controlled input.