CVE-2020-8203

Aliases:GHSA-p6mc-m468-83gw
Modified
Published: 15 Jul 2020, 16:10
Last modified:04 Aug 2024, 09:56

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.4 HIGH
v3.1 (nvd)
EPSS Score
2.55% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

15 Jul 2020, 16:10
Published
Vulnerability first disclosed
04 Aug 2024, 09:56
Last Modified
Vulnerability information updated

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 2.55% Percentile: 86%

Techniques & Countermeasures

  • CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • RubyGemslodash-rails

    ≥ 3.7.0, < 4.17.19

  • lodashlodash

    < 4.17.20

  • Npmlodash

    ≥ 3.7.0, < 4.17.19

  • Npmlodash-es

    ≥ 3.7.0, < 4.17.20

  • Npmlodash.pick

    ≥ 4.0.0, ≤ 4.4.0

  • Npmlodash.set

    ≥ 3.7.0, ≤ 4.3.2

  • Npmlodash.setwith

    ≤ 4.3.2

  • Npmlodash.update

    ≤ 4.10.2

  • Npmlodash.updatewith

    ≤ 4.10.2

  • oraclebanking_corporate_lending_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_credit_facilities_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_extensibility_workbench

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_liquidity_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_supply_chain_finance

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_trade_finance_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_virtual_account_management

    14.2.0 | 14.3.0 | 14.5.0

  • oracleblockchain_platform

    < 21.1.2

  • oraclecommunications_billing_and_revenue_management

    7.5.0.23.0 | 12.0.0.3.0

  • oraclecommunications_cloud_native_core_policy

    1.11.0

  • oraclecommunications_session_border_controller

    8.4 | 9.0 | cz8.4

  • oraclecommunications_session_router

    cz8.4

  • oraclecommunications_subscriber-aware_load_balancer

    cz8.3 | cz8.4

  • oracleenterprise_communications_broker

    3.2.0 | 3.3.0 | pcz3.3

  • oraclejd_edwards_enterpriseone_tools

    ≤ 9.2.6.0

  • oraclepeoplesoft_enterprise_peopletools

    8.58 | 8.59

  • oracleprimavera_gateway

    ≥ 17.12.0, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.12 | ≥ 19.12.0, ≤ 19.12.11 | ≥ 20.12.0, ≤ 20.12.7

  • wordpresswordpress

    ≥ 5.4, < 5.4.7 | ≥ 5.5, < 5.5.6 | ≥ 5.6, < 5.6.5 | ≥ 5.7, < 5.7.3 | ≥ 5.8, < 5.8.1

References (19)