ZeroHour

CVE-2020-8203

PoC
CVSS 3.1
7.4 high
EPSS
5%p92
Published
()
Modified
Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Vendors
lodashoracle
Products
lodash, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking liquidity management, banking supply chain finance, banking trade finance process management, banking virtual account management, blockchain platform, communications billing and revenue management, communications cloud native core policy, communications session border controller
Weakness
CWE-770, CWE-1321
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.