CVE-2020-28500
Aliases:GHSA-29mw-wpgm-hmr9
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 15 Feb 2021, 11:10
Last modified:16 Sept 2024, 22:15
Vulnerability Summary
Overall Risk (default)
medium
33/100 CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
7.34% LOW
7% probability +7.09%
KEV
Not listed
Ransomware
No reports
Public exploits
6 found
Dark Web
Not detected
Timeline
15 Feb 2021, 11:10
Published
Vulnerability first disclosed
16 Sept 2024, 22:15
Last Modified
Vulnerability information updated
Description
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 7.34%• Percentile: 94%
Affected Systems
- RubyGems•lodash-rails
≥ 4.0.0, < 4.17.21
- lodash•lodash
< 4.17.21
- Npm•lodash
≥ 4.0.0, < 4.17.21
- Npm•lodash-es
≥ 4.0.0, < 4.17.21
- Npm•lodash.trim
≥ 4.0.0, ≤ 4.5.1
- Npm•lodash.trimend
≥ 4.0.0, ≤ 4.5.1
- oracle•banking_corporate_lending_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_credit_facilities_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_extensibility_workbench
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_supply_chain_finance
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_trade_finance_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•communications_cloud_native_core_policy
1.11.0
- oracle•communications_design_studio
7.4.2
- oracle•communications_services_gatekeeper
7.0
- oracle•communications_session_border_controller
8.4 | 9.0
- oracle•enterprise_communications_broker
3.2.0 | 3.3.0
- oracle•financial_services_crime_and_compliance_management_studio
8.0.8.2.0 | 8.0.8.3.0
- oracle•health_sciences_data_management_workbench
2.5.2.1 | 3.0.0.0
- oracle•jd_edwards_enterpriseone_tools
< 9.2.6.1
- Unknown•PeopleSoft Enterprise PeopleTools
8.58 | 8.59
- oracle•primavera_gateway
≥ 17.12.0, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.12 | ≥ 19.12.0, ≤ 19.12.11 | ≥ 20.12.0, ≤ 20.12.7
- oracle•primavera_unifier
≥ 17.7, ≤ 17.12 | 18.8 | 19.12 | 20.12
- oracle•retail_customer_management_and_segmentation_foundation
19.0
- siemens•sinec_ins
< 1.0 | 1.0 | 1.0:sp1
References (21)
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896
- https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8
- https://github.com/lodash/lodash/pull/5065
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://security.netapp.com/advisory/ntap-20210312-0006/
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://nvd.nist.gov/vuln/detail/CVE-2020-28500
- https://github.com/github/advisory-database/pull/6139
- https://github.com/lodash/lodash/pull/5065/commits/02906b8191d3c100c193fe6f7b27d1c40f200bb7
- https://github.com/lodash/lodash/commit/c4847ebe7d14540bb28a8b932a9ce1b9ecbfee1a
- https://security.netapp.com/advisory/ntap-20210312-0006
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-28500.yml
- https://github.com/lodash/lodash