Get real-time updates on Telegram
CVE-2020-28500: lodash before 4.17.21 (exclusive); +19 more affected products
CVE-2020-28500. CVSS 3.1 base score 5.3 (MEDIUM, NVD). EPSS 0.07336 (percentile 0.94244), scored 2026-10-08.
Affected technology
lodash · before 4.17.21 (exclusive)
lodash
banking corporate lending process management · 14.2.0
oracle
banking corporate lending process management · 14.3.0
oracle
banking corporate lending process management · 14.5.0
oracle
banking credit facilities process management · 14.2.0
oracle
banking credit facilities process management · 14.3.0
oracle
banking credit facilities process management · 14.5.0
oracle
banking extensibility workbench · 14.2.0
oracle
banking extensibility workbench · 14.3.0
oracle
banking extensibility workbench · 14.5.0
oracle
banking supply chain finance · 14.2.0
oracle
banking supply chain finance · 14.3.0
oracle
banking supply chain finance · 14.5.0
oracle
banking trade finance process management · 14.2.0
oracle
banking trade finance process management · 14.3.0
oracle
banking trade finance process management · 14.5.0
oracle
communications cloud native core policy · 1.11.0
oracle
communications design studio · 7.4.2
oracle
communications services gatekeeper · 7.0
oracle
communications session border controller · 8.4
oracle
communications session border controller · 9.0
oracle
enterprise communications broker · 3.2.0
oracle
enterprise communications broker · 3.3.0
oracle
financial services crime and compliance management studio · 8.0.8.2.0
oracle
financial services crime and compliance management studio · 8.0.8.3.0
oracle
health sciences data management workbench · 2.5.2.1
oracle
health sciences data management workbench · 3.0.0.0
oracle
jd edwards enterpriseone tools · before 9.2.6.1 (exclusive)
oracle
peoplesoft enterprise peopletools · 8.58
oracle
peoplesoft enterprise peopletools · 8.59
oracle
primavera gateway · from 17.12.0 (inclusive), through 17.12.11 (inclusive)
oracle
primavera gateway · from 18.8.0 (inclusive), through 18.8.12 (inclusive)
oracle
primavera gateway · from 19.12.0 (inclusive), through 19.12.11 (inclusive)
oracle
primavera gateway · from 20.12.0 (inclusive), through 20.12.7 (inclusive)
oracle
primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle
primavera unifier · 18.8
oracle
primavera unifier · 19.12
oracle
primavera unifier · 20.12
oracle
retail customer management and segmentation foundation · 19.0
oracle
sinec ins · before 1.0 (exclusive)
siemens
sinec ins · 1.0
siemens
sinec ins · 1.0 · update sp1
siemens
Lodash · versions prior to 4.17.21
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low. NVD’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- CCR priority
- 23.0 /100 (P4)
- CVSS 3.1
- 5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · NVD
- EPSS
- 0.07336 · percentile 0.94244 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-28500.html