HIGH · 7.4

CVE-2020-8203

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Vulnerability Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LodashLodash< 4.17.20
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Extensibility Workbench14.2.0
OracleBanking Liquidity Management14.2.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Trade Finance Process Management14.2.0
OracleBanking Virtual Account Management14.2.0
OracleBlockchain Platform< 21.1.2
OracleCommunications Billing And Revenue Management7.5.0.23.0
OracleCommunications Cloud Native Core Policy1.11.0
OracleCommunications Session Border Controller8.4
OracleCommunications Session Routercz8.4
OracleCommunications Subscriber-Aware Load Balancercz8.3
OracleEnterprise Communications Broker3.2.0
OracleJd Edwards Enterpriseone Tools<= 9.2.6.0
OraclePeoplesoft Enterprise Peopletools8.58
OraclePrimavera Gateway>= 17.12.0, <= 17.12.11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8203?

CVE-2020-8203 is a vulnerability with a CVSS score of 7.4 (HIGH). Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

How severe is CVE-2020-8203?

CVE-2020-8203 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8203?

Check the references section above for vendor advisories and patch information. Affected products include: Lodash Lodash, Oracle Banking Corporate Lending Process Management, Oracle Banking Credit Facilities Process Management, Oracle Banking Extensibility Workbench, Oracle Banking Liquidity Management.