CVE-2020-8203

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

Risk Information

Base Score
7.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
2.546

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0.9.2Windows
Vulnerabilities CVE-2020-8203 are fixed in Ruby-lodash-rails 4.17.19Windows
Vulnerabilities CVE-2020-8203 are fixed in Ruby-lodash-rails for Linux 4.17.19Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234