MEDIUM · 5.3

CVE-2020-28500

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Vulnerability Description

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
LodashLodash< 4.17.21
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Extensibility Workbench14.2.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Trade Finance Process Management14.2.0
OracleCommunications Cloud Native Core Policy1.11.0
OracleCommunications Design Studio7.4.2
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Border Controller8.4
OracleEnterprise Communications Broker3.2.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleHealth Sciences Data Management Workbench2.5.2.1
OracleJd Edwards Enterpriseone Tools< 9.2.6.1
OraclePeoplesoft Enterprise Peopletools8.58
OraclePrimavera Gateway>= 17.12.0, <= 17.12.11
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleRetail Customer Management And Segmentation Foundation19.0
SiemensSinec Ins< 1.0

References

FAQ

What is CVE-2020-28500?

CVE-2020-28500 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

How severe is CVE-2020-28500?

CVE-2020-28500 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28500?

Check the references section above for vendor advisories and patch information. Affected products include: Lodash Lodash, Oracle Banking Corporate Lending Process Management, Oracle Banking Credit Facilities Process Management, Oracle Banking Extensibility Workbench, Oracle Banking Supply Chain Finance.