CVE-2020-8203Allocation of Resources Without Limits or Throttling in Lodash

Severity
7.4HIGHNVD
EPSS
3.2%
top 12.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateApr 15

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 2.2 | Impact: 5.2

Affected Packages20 packages

NVDlodash/lodash< 4.17.20
npmlodash/lodash3.7.04.17.19
CVEListV5lodash/lodashNot Fixed
NVDoracle/primavera_gateway17.12.017.12.11+3

Patches

🔴Vulnerability Details

4
CVEList
CVE-2020-8203: Prototype pollution attack when using _2020-07-15
GHSA
Prototype Pollution in lodash2020-07-15
OSV
CVE-2020-8203: Prototype pollution attack when using _2020-07-15
OSV
Prototype Pollution in lodash2020-07-15

📋Vendor Advisories

6
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Lodash) — CVE-2020-82032022-04-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Account (Lodash) — CVE-2020-82032021-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Billing Care (Lodash) — CVE-2020-82032021-07-15
Oracle
Oracle Oracle Communications Risk Matrix: Routing (Lodash) — CVE-2020-82032021-04-15
Red Hat
nodejs-lodash: prototype pollution in zipObjectDeep function2020-04-27

💬Community

2
Bugzilla
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function [epel-all]2020-07-23
Bugzilla
CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function2020-07-15
CVE-2020-8203 — Lodash vulnerability | cvebase