CVE-2020-8203
published 2020-07-15CVE-2020-8203: Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
PriorityP343high7.4CVSS 3.1
AVNACHPRNUINSUCNIHAH
EPSS
5.21%
91.6th percentile
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-lodash | < node-lodash 4.17.19+dfsg-1 (bookworm) | node-lodash 4.17.19+dfsg-1 (bookworm) |
| lodash | lodash | < 4.17.20 | 4.17.20 |
| lodash | lodash | — | — |
| lodash | lodash | >= 3.7.0 < 4.17.19 | 4.17.19 |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_liquidity_management | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_trade_finance_process_management | — | — |
| oracle | banking_trade_finance_process_management | — | — |
| oracle | banking_trade_finance_process_management | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | banking_virtual_account_management | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.4HIGH
vendor_debian7.4HIGH
vendor_oracle7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Prototype Pollution in lodash
ghsa·2020-07-15
CVE-2020-8203 [HIGH] CWE-1321 Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions `pick`, `set`, `setWith`, `update`, `updateWith`, and `zipObjectDeep` allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays.
This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
OSV
CVE-2020-8203: Prototype pollution attack when using _
osv·2020-07-15·CVSS 7.4
CVE-2020-8203 [HIGH] CVE-2020-8203: Prototype pollution attack when using _
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
OSV
Prototype Pollution in lodash
osv·2020-07-15
CVE-2020-8203 [HIGH] Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions `pick`, `set`, `setWith`, `update`, `updateWith`, and `zipObjectDeep` allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays.
This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
Ubuntu
Lodash vulnerabilities
vendor_ubuntu·2026-06-09·CVSS 5.3
CVE-2025-13465 [MEDIUM] Lodash vulnerabilities
Title: Lodash vulnerabilities
Summary: Several security issues were fixed in Lodash.
It was discovered that Lodash was vulnerable to a prototype pollution
issue in the zipObjectDeep function. An attacker could possibly use this
issue to modify application behavior. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8203)
Liyuan Chen discovered that Lodash was vulnerable to a regular
expression denial of service issue in the toNumber, trim, and trimEnd
functions. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-28500)
Marc Hassan discovered that Lodash did not properly sanitize input to
the template function. An attacker could
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Lodash) — CVE-2020-8203
vendor_oracle·2022-04-15·CVSS 7.4
CVE-2020-8203 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Lodash) — CVE-2020-8203
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Lodash) vulnerability
CVE: CVE-2020-8203
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Account (Lodash) — CVE-2020-8203
vendor_oracle·2021-10-15·CVSS 7.4
CVE-2020-8203 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Account (Lodash) — CVE-2020-8203
Oracle Oracle Financial Services Applications Risk Matrix: Account (Lodash) vulnerability
CVE: CVE-2020-8203
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Billing Care (Lodash) — CVE-2020-8203
vendor_oracle·2021-07-15·CVSS 7.4
CVE-2020-8203 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Billing Care (Lodash) — CVE-2020-8203
Oracle Oracle Communications Applications Risk Matrix: Billing Care (Lodash) vulnerability
CVE: CVE-2020-8203
CVSS: 7.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Routing (Lodash) — CVE-2020-8203
vendor_oracle·2021-04-15·CVSS 6.4
CVE-2020-8203 [HIGH] Oracle Oracle Communications Risk Matrix: Routing (Lodash) — CVE-2020-8203
Oracle Oracle Communications Risk Matrix: Routing (Lodash) vulnerability
CVE: CVE-2020-8203
CVSS: 6.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
nodejs-lodash: prototype pollution in zipObjectDeep function
vendor_redhat·2020-04-27·CVSS 7.4
CVE-2020-8203 [HIGH] CWE-20 nodejs-lodash: prototype pollution in zipObjectDeep function
nodejs-lodash: prototype pollution in zipObjectDeep function
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
A flaw was found in nodejs-lodash in versions 4.17.15 and earlier. A prototype pollution attack is possible which can lead to arbitrary code execution. The primary threat from this vulnerability is to data integrity and system availability.
Statement: In OpenShift ServiceMesh (OSSM), Red Hat OpenShift Jaeger (RHOSJ) and Red Hat OpenShift Container Platform (RHOCP), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low.
Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-lodash library is
Debian
CVE-2020-8203: node-lodash - Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
vendor_debian·2020·CVSS 7.4
CVE-2020-8203 [HIGH] CVE-2020-8203: node-lodash - Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Scope: local
bookworm: resolved (fixed in 4.17.19+dfsg-1)
bullseye: resolved (fixed in 4.17.19+dfsg-1)
forky: resolved (fixed in 4.17.19+dfsg-1)
sid: resolved (fixed in 4.17.19+dfsg-1)
trixie: resolved (fixed in 4.17.19+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function [epel-all]
bugzilla·2020-07-23·CVSS 7.4
CVE-2020-8203 [HIGH] CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function [epel-all]
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function
bugzilla·2020-07-15·CVSS 7.4
CVE-2020-8203 [HIGH] CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function
Prototype pollution attack when using _.zipObjectDeep in lodash AC:H
To exploit this vulnerability the attacker must to zip object based on user-provided property arrays, which means somehow must to guess the array properties first.
---
Statement:
In OpenShift ServiceMesh (OSSM), Red Hat OpenShift Jaeger (RHOSJ) and Red Hat OpenShift Container Platform (RHOCP), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low.
Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-lodash library is used, but due to the code changing to the container first content t
Tenable
Identifying Prototype Pollution Vulnerabilities: How Tenable.io Web Application Scanning Can Help
blogs_tenable·2021-05-25
Identifying Prototype Pollution Vulnerabilities: How Tenable.io Web Application Scanning Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://github.com/lodash/lodash/issues/4874https://hackerone.com/reports/712065https://security.netapp.com/advisory/ntap-20200724-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/lodash/lodash/issues/4874https://hackerone.com/reports/712065https://security.netapp.com/advisory/ntap-20200724-0006/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-07-15
Published