← Back

CVE-2020-28500

nvd nist
Published: Feb 15, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Affected (42)

1 product
Lodash
17 products
1 product
Sinec Ins
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.17.21
Configuration B
38 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Version 1.11.0
Version 7.4.2
Version 7.0
Oracle
Version 8.4
Version 9.0
Oracle
Version 3.2.0
Version 3.3.0
Oracle
Version 8.0.8.2.0
Version 8.0.8.3.0
Oracle
Version 2.5.2.1
Version 3.0.0.0
Before 9.2.6.1
Oracle
Version 8.58
Version 8.59
Oracle
From 17.12.0 to 17.12.11
From 18.8.0 to 18.8.12
From 19.12.0 to 19.12.11
From 20.12.0 to 20.12.7
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Version 19.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Before 1.0
Version 1.0
Version 1.0 sp1

References (28)

Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
Third Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
Not ApplicableThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.