CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2020-28500: lodash before 4.17.21 (exclusive); +19 more affected products

CVE-2020-28500. CVSS 3.1 base score 5.3 (MEDIUM, NVD). EPSS 0.07336 (percentile 0.94244), scored 2026-10-08.

Affected technology

lodash · before 4.17.21 (exclusive)
lodash

banking corporate lending process management · 14.2.0
oracle

banking corporate lending process management · 14.3.0
oracle

banking corporate lending process management · 14.5.0
oracle

banking credit facilities process management · 14.2.0
oracle

banking credit facilities process management · 14.3.0
oracle

banking credit facilities process management · 14.5.0
oracle

banking extensibility workbench · 14.2.0
oracle

banking extensibility workbench · 14.3.0
oracle

banking extensibility workbench · 14.5.0
oracle

banking supply chain finance · 14.2.0
oracle

banking supply chain finance · 14.3.0
oracle

banking supply chain finance · 14.5.0
oracle

banking trade finance process management · 14.2.0
oracle

banking trade finance process management · 14.3.0
oracle

banking trade finance process management · 14.5.0
oracle

communications cloud native core policy · 1.11.0
oracle

communications design studio · 7.4.2
oracle

communications services gatekeeper · 7.0
oracle

communications session border controller · 8.4
oracle

communications session border controller · 9.0
oracle

enterprise communications broker · 3.2.0
oracle

enterprise communications broker · 3.3.0
oracle

financial services crime and compliance management studio · 8.0.8.2.0
oracle

financial services crime and compliance management studio · 8.0.8.3.0
oracle

health sciences data management workbench · 2.5.2.1
oracle

health sciences data management workbench · 3.0.0.0
oracle

jd edwards enterpriseone tools · before 9.2.6.1 (exclusive)
oracle

peoplesoft enterprise peopletools · 8.58
oracle

peoplesoft enterprise peopletools · 8.59
oracle

primavera gateway · from 17.12.0 (inclusive), through 17.12.11 (inclusive)
oracle

primavera gateway · from 18.8.0 (inclusive), through 18.8.12 (inclusive)
oracle

primavera gateway · from 19.12.0 (inclusive), through 19.12.11 (inclusive)
oracle

primavera gateway · from 20.12.0 (inclusive), through 20.12.7 (inclusive)
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 18.8
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

retail customer management and segmentation foundation · 19.0
oracle

sinec ins · before 1.0 (exclusive)
siemens

sinec ins · 1.0
siemens

sinec ins · 1.0 · update sp1
siemens

Lodash · versions prior to 4.17.21
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low. NVD’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CCR priority
23.0 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · NVD
EPSS
0.07336 · percentile 0.94244 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-28500.html