Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
cockpit-389-ds doesn't use lodash directly. It's only a transitive dependency of PatternFly (@patternfly/react-charts, @patternfly/react-table) and victory-* chart libraries. It's also used by dev dependencies: eslint (lodash.merge) and table (lodash.truncate). The vulnerability is in _.template(), none of the transitive consumers use lodash.template(). Closing as not a bug.