cbcvebase.
CVE-2020-28500
published 2021-02-15

CVE-2020-28500: Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
7.34%
93.7th percentile
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debiannode-lodash< node-lodash 4.17.21+dfsg+~cs8.31.173-1 (bookworm)node-lodash 4.17.21+dfsg+~cs8.31.173-1 (bookworm)
lodashlodash< 4.17.214.17.21
lodashlodash
lodashlodash>= 4.0.0 < 4.17.214.17.21
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_extensibility_workbench
oraclebanking_extensibility_workbench
oraclebanking_extensibility_workbench
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclecommunications_cloud_native_core_policy
oraclecommunications_design_studio
oraclecommunications_services_gatekeeper
oraclecommunications_session_border_controller
oraclecommunications_session_border_controller
oracleenterprise_communications_broker

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.