Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This is almost surely a N/A for cockpit and the similar bugs filed against the other projects. Alexandra, can you please find someone to triage this? Thanks!
This does not affect Cockpit as it requires arbitrary code execution in the browser already via XSS. Meanwhile we have updated lodash to >= 4.18.1 in Cockpit 360 which resolves this issue.