CVE-2020-8203

Source
https://cve.org/CVERecord?id=CVE-2020-8203
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-8203.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-8203
Aliases
Downstream
Published
2020-07-15T17:15:11.797Z
Modified
2026-05-28T04:06:16.807627224Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "21.1.2"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:blockchain_platform"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "9.2.6.0"
                }
            ],
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:jd_edwards_enterpriseone_tools"
        },
        {
            "source": "CPE_RANGE",
            "extracted_events": [
                {
                    "introduced": "17.12.0"
                },
                {
                    "last_affected": "17.12.11"
                },
                {
                    "introduced": "18.8.0"
                },
                {
                    "last_affected": "18.8.12"
                },
                {
                    "introduced": "19.12.0"
                },
                {
                    "last_affected": "19.12.11"
                },
                {
                    "introduced": "20.12.0"
                },
                {
                    "last_affected": "20.12.7"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:primavera_gateway"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_corporate_lending_process_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_credit_facilities_process_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_extensibility_workbench"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_liquidity_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_liquidity_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_liquidity_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_liquidity_management"
        },
        {
            "source": "CPE_STRING",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_supply_chain_finance"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_trade_finance_process_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:banking_virtual_account_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "7.5.0.23.0"
                },
                {
                    "last_affected": "12.0.0.3.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:communications_billing_and_revenue_management"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "1.11.0"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.11.0:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:communications_cloud_native_core_policy"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "8.4"
                },
                {
                    "last_affected": "9.0"
                },
                {
                    "last_affected": "cz8.4"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:communications_session_border_controller:8.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_session_border_controller:9.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_session_border_controller:cz8.4:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:communications_session_border_controller"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "cz8.4"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:communications_session_router:cz8.4:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:communications_session_router"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "cz8.3"
                },
                {
                    "last_affected": "cz8.4"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:communications_subscriber-aware_load_balancer:cz8.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_subscriber-aware_load_balancer:cz8.4:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:communications_subscriber-aware_load_balancer"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "3.2.0"
                },
                {
                    "last_affected": "3.3.0"
                },
                {
                    "last_affected": "pcz3.3"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:enterprise_communications_broker:3.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:enterprise_communications_broker:pcz3.3:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:enterprise_communications_broker"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "8.58"
                },
                {
                    "last_affected": "8.59"
                }
            ],
            "source": "CPE_STRING",
            "cpes": [
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
            ],
            "vendor_product": "oracle:peoplesoft_enterprise_peopletools"
        }
    ]
}
References

Affected packages

Git / github.com/lodash/lodash

Affected ranges

Type
GIT
Repo
https://github.com/lodash/lodash
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.17.20"
        }
    ]
}

Affected versions

3.*
3.0.0-npm
3.0.1-npm
3.1.0-npm
3.10.0-npm
3.10.1-npm
3.2.0-npm
3.3.0-npm
3.3.1-npm
3.4.0-npm
3.5.0-npm
3.6.0-npm
3.7.0-npm
3.8.0-npm
3.9.0-npm
3.9.1-npm
3.9.2-npm
3.9.3-npm
4.*
4.0.0-npm
4.0.1-npm
4.1.0-npm
4.10.0-npm
4.11.0-npm
4.11.1-npm
4.11.2-npm
4.12.0-npm
4.13.0-npm
4.13.1-npm
4.14.0-npm
4.14.1-npm
4.14.2-npm
4.15.0-npm
4.16.0-npm
4.16.1-npm
4.16.2-npm
4.16.3-npm
4.16.4-npm
4.16.5-npm
4.16.6-npm
4.17.0-npm
4.17.1-npm
4.17.10-npm
4.17.11-npm
4.17.12-npm
4.17.13-npm
4.17.14-npm
4.17.15-npm
4.17.2-npm
4.17.3-npm
4.17.4-npm
4.17.5-npm
4.17.9-npm
4.2.0-npm
4.2.1-npm
4.3.0-npm
4.4.0-npm
4.5.0-npm
4.5.1-npm
4.6.0-npm
4.6.1-npm
4.7.0-npm
4.8.0-npm
4.8.1-npm
4.8.2-npm
4.9.0-npm

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-8203.json"