CVE-2020-28500
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Affected (42)
Products: Lodash: Lodash · Oracle: Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Extensibility Workbench, Banking Supply Chain Finance, Banking Trade Finance Process Management, Communications Cloud Native Core Policy, Communications Design Studio, Communications Services Gatekeeper, Communications Session Border Controller, Enterprise Communications Broker, Financial Services Crime And Compliance Management Studio, Health Sciences Data Management Workbench, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Customer Management And Segmentation Foundation · Siemens: Sinec Ins
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 1.11.0 | |
| Version 7.4.2 | |
| Version 7.0 | |
| Version 8.4 | |
| Version 3.2.0 | |
| Version 8.0.8.2.0 | |
| Version 2.5.2.1 | |
| Before 9.2.6.1 | |
| Version 8.58 | |
| From 17.12.0 to 17.12.11 | |
| From 17.7 to 17.12 | |
| Version 19.0 |
References (28)
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
Not ApplicableThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.