SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-28500

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

MEDIUM 5.3EPSS 7.34%

Does this matter?

Lower severity and a low EPSS score (7.34%). Track it; it rarely justifies an emergency change on its own.

Description

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
7.34% probability · 94th percentile
CISA KEV
Not listed
Affected
lodash/lodash · oracle/banking corporate lending process management · oracle/banking credit facilities process management · oracle/banking extensibility workbench · oracle/banking supply chain finance · oracle/banking trade finance process management · oracle/communications cloud native core policy · oracle/communications design studio · oracle/communications services gatekeeper · oracle/communications session border controller · oracle/enterprise communications broker · oracle/financial services crime and compliance management studio · oracle/health sciences data management workbench · oracle/jd edwards enterpriseone tools · oracle/peoplesoft enterprise peopletools · oracle/primavera gateway · oracle/primavera unifier · oracle/retail customer management and segmentation foundation · siemens/sinec ins
Source
report@snyk.io

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.