ZeroHour

CVE-2020-28500

PoC ×6
CVSS 3.1
5.3 medium
EPSS
7%p94
Published
()
Modified
Description

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Vendors
lodashoraclesiemens
Products
lodash, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking supply chain finance, banking trade finance process management, communications cloud native core policy, communications design studio, communications services gatekeeper, communications session border controller, enterprise communications broker, financial services crime and compliance management studio
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.