CVE-2020-8203
Vulnerability Summary
Timeline
Description
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
- v3.1•MEDIUM•Score: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- v2.0•MEDIUM•Score: 5.8AV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS Trends
Current EPSS score: 2.55%• Percentile: 86%
Techniques & Countermeasures
- CWE-1321•Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
- CWE-79•Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- RubyGems•lodash-rails
≥ 3.7.0, < 4.17.19
- lodash•lodash
< 4.17.20
- Npm•lodash
≥ 3.7.0, < 4.17.19
- Npm•lodash-es
≥ 3.7.0, < 4.17.20
- Npm•lodash.pick
≥ 4.0.0, ≤ 4.4.0
- Npm•lodash.set
≥ 3.7.0, ≤ 4.3.2
- Npm•lodash.setwith
≤ 4.3.2
- Npm•lodash.update
≤ 4.10.2
- Npm•lodash.updatewith
≤ 4.10.2
- oracle•banking_corporate_lending_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_credit_facilities_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_extensibility_workbench
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_liquidity_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_supply_chain_finance
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_trade_finance_process_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•banking_virtual_account_management
14.2.0 | 14.3.0 | 14.5.0
- oracle•blockchain_platform
< 21.1.2
- oracle•communications_billing_and_revenue_management
7.5.0.23.0 | 12.0.0.3.0
- oracle•communications_cloud_native_core_policy
1.11.0
- oracle•communications_session_border_controller
8.4 | 9.0 | cz8.4
- oracle•communications_session_router
cz8.4
- oracle•communications_subscriber-aware_load_balancer
cz8.3 | cz8.4
- oracle•enterprise_communications_broker
3.2.0 | 3.3.0 | pcz3.3
- oracle•jd_edwards_enterpriseone_tools
≤ 9.2.6.0
- oracle•peoplesoft_enterprise_peopletools
8.58 | 8.59
- oracle•primavera_gateway
≥ 17.12.0, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.12 | ≥ 19.12.0, ≤ 19.12.11 | ≥ 20.12.0, ≤ 20.12.7
- wordpress•wordpress
≥ 5.4, < 5.4.7 | ≥ 5.5, < 5.5.6 | ≥ 5.6, < 5.6.5 | ≥ 5.7, < 5.7.3 | ≥ 5.8, < 5.8.1
References (19)
- https://hackerone.com/reports/712065
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://security.netapp.com/advisory/ntap-20200724-0006/
- https://github.com/lodash/lodash/issues/4874
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://nvd.nist.gov/vuln/detail/CVE-2020-8203
- https://github.com/lodash/lodash/issues/4744
- https://github.com/github/advisory-database/pull/2884
- https://github.com/lodash/lodash/commit/c84fe82760fb2d3e03a63379b297a1cc1a2fce12
- https://hackerone.com/reports/864701
- https://github.com/lodash/lodash
- https://github.com/lodash/lodash/wiki/Changelog#v41719
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-8203.yml
- https://security.netapp.com/advisory/ntap-20200724-0006
- https://web.archive.org/web/20210914001339/https://github.com/lodash/lodash/issues/4744
- https://www.wordfence.com/threat-intel/vulnerabilities/id/51cd834e-1b18-4702-9c6c-db7f34f2c687