Skip to content

CX: CVE-2020-8203 in Npm-lodash and 1.0.2 @ JavaVulnerableLab.master #172

@satyamchaurasiapersistent

Description

Description

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.

HIGH Vulnerable Package issue exists @ lodash in branch master

Vulnerability ID: CVE-2020-8203

Package Name: lodash

Severity: HIGH

CVSS Score: 7.4

Publish Date: 2020-07-15T17:15:00

Current Package Version: 1.0.2

Remediation Upgrade Recommendation: 4.17.21

Link To SCA

Reference – NVD link

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions