Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2020-8203
CVE information
Published
Last Modified
CVSSv2.0 Severity
CVSSv3.1 Severity
Impact Analysis
Description
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5.8/10
- Exploit Score
- 8.6/10
- Access Vector
- Network
- Access Complexity
- Medium
- Authentication Required
- None
- Impact Score
- 4.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- Partial
CVSSv3.1 Score
- Severity
- High
- Base Score
- 7.4/10
- Exploit Score
- 2.2/10
- Access Vector
- Network
- Access Complexity
- High
- Privileges Required
- None
- Impact Score
- 5.2/10
- Confidentiality Impact
- None
- Availability Impact
- High
- Integrity Impact
- High
- Scope
- Unchanged
- User Interaction
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:* |
Yes
|
- | 4.17.20 | |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_billing_and_revenue_manageme |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_billing_and_revenue_manageme |
Yes
|
- | - | |
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14 |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
Yes
|
17.12.0 | - | |
cpe:2.3:a:oracle:enterprise_communications_broker:pcz3.3:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_subscriber-aware_load_balanc |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_subscriber-aware_load_balanc |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_session_router:cz8.4:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_session_border_controller:cz |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_session_border_controller:8. |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_session_border_controller:9. |
Yes
|
- | - | |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
Yes
|
20.12.0 | - | |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
Yes
|
19.12.0 | - | |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:* |
Yes
|
18.8.0 | - | |
cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14 |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_credit_facilities_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_corporate_lending_process_managemen |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14 |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:enterprise_communications_broker:3.3.0:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.1 |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_liquidity_management:14.2.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_liquidity_management:14.5.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:banking_liquidity_management:14.3.0:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* |
Yes
|
- | 21.1.2 |
References
- https://hackerone.com/reports/712065
- https://security.netapp.com/advisory/ntap-20200724-0006/
- https://github.com/lodash/lodash/issues/4874
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html