Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2020-8203

CVE information

Published

3 years ago

Last Modified

3 months ago

CVSSv2.0 Severity

Medium

CVSSv3.1 Severity

High

Impact Analysis

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20..

CVSSv2.0 Score

Severity
Medium
Base Score
5.8/10
Exploit Score
8.6/10
Access Vector
Network
Access Complexity
Medium
Authentication Required
None
Impact Score
4.9/10
Confidentiality Impact
None
Availability Impact
Partial
Integrity Impact
Partial

CVSSv3.1 Score

Severity
High
Base Score
7.4/10
Exploit Score
2.2/10
Access Vector
Network
Access Complexity
High
Privileges Required
None
Impact Score
5.2/10
Confidentiality Impact
None
Availability Impact
High
Integrity Impact
High
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*
  Yes
- 4.17.20
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:
  Yes
- -
cpe:2.3:a:oracle:communications_billing_and_revenue_manageme
  Yes
- -
cpe:2.3:a:oracle:communications_billing_and_revenue_manageme
  Yes
- -
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*
  Yes
- -
cpe:2.3:a:oracle:banking_trade_finance_process_management:14
  Yes
- -
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen
  Yes
- -
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen
  Yes
- -
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:
  Yes
- -
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
  Yes
17.12.0 -
cpe:2.3:a:oracle:enterprise_communications_broker:pcz3.3:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_subscriber-aware_load_balanc
  Yes
- -
cpe:2.3:a:oracle:communications_subscriber-aware_load_balanc
  Yes
- -
cpe:2.3:a:oracle:communications_session_router:cz8.4:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:communications_session_border_controller:cz
  Yes
- -
cpe:2.3:a:oracle:communications_session_border_controller:8.
  Yes
- -
cpe:2.3:a:oracle:communications_session_border_controller:9.
  Yes
- -
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
  Yes
20.12.0 -
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
  Yes
19.12.0 -
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
  Yes
18.8.0 -
cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*
  Yes
- -
cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*
  Yes
- -
cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_trade_finance_process_management:14
  Yes
- -
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen
  Yes
- -
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen
  Yes
- -
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen
  Yes
- -
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen
  Yes
- -
cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_trade_finance_process_management:14
  Yes
- -
cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:enterprise_communications_broker:3.3.0:*:*:
  Yes
- -
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.1
  Yes
- -
cpe:2.3:a:oracle:banking_liquidity_management:14.2.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_liquidity_management:14.5.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:banking_liquidity_management:14.3.0:*:*:*:*
  Yes
- -
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:
  Yes
- -
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*
  Yes
- 21.1.2