cbcvebase.
CVE-2020-8203
published 2020-07-15

CVE-2020-8203: Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

high7.4CVSS 3.1
AVNACHPRNUINSUCNIHAH
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debiannode-lodash< node-lodash 4.17.19+dfsg-1 (bookworm)node-lodash 4.17.19+dfsg-1 (bookworm)
lodashlodash< 4.17.204.17.20
lodashlodash
lodashlodash>= 3.7.0 < 4.17.194.17.19
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_extensibility_workbench
oraclebanking_extensibility_workbench
oraclebanking_extensibility_workbench
oraclebanking_liquidity_management
oraclebanking_liquidity_management
oraclebanking_liquidity_management
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management
oraclebanking_virtual_account_management

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
osv7.4HIGH