CVE Vulnerabilities

CVE-2020-28500

Published: Feb 15, 2021 | Modified: Sep 13, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Affected Software

Name Vendor Start Version End Version
Lodash Lodash * 4.17.21 (excluding)
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat acmesolver-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat acm-must-gather-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat acm-operator-bundle-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat application-ui-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat cainjector-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat cert-manager-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat cert-manager-webhook-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat cert-policy-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat clusterlifecycle-state-metrics-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat configmap-watcher-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat config-policy-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat console-api-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat console-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat console-header-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat endpoint-component-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat endpoint-monitoring-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat endpoint-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat governance-policy-propagator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat governance-policy-spec-sync-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat governance-policy-status-sync-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat governance-policy-template-sync-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat grafana-dashboard-loader-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat grc-ui-api-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat grc-ui-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat iam-policy-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat klusterlet-addon-lease-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat klusterlet-operator-bundle-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat kui-web-terminal-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat management-ingress-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat mcm-topology-api-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat mcm-topology-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat memcached-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat memcached-exporter-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat metrics-collector-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicloud-manager-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multiclusterhub-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multiclusterhub-repo-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-observability-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-application-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-channel-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-deployable-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-placementrule-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-subscription-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat multicluster-operators-subscription-release-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat observatorium-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat observatorium-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat openshift-hive-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat rbac-query-proxy-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat rcm-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat redisgraph-tls-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat registration-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat registration-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat search-aggregator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat search-api-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat search-collector-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat search-operator-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat search-ui-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat submariner-addon-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat thanos-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat thanos-receive-controller-container *
Red Hat Advanced Cluster Management for Kubernetes 2 RedHat work-container *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/application-ui-rhel8:v2.3.0-120 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/console-api-rhel8:v2.3.0-63 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/kui-web-terminal-rhel8:v2.3.0-51 *
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 RedHat rhacm2/search-api-rhel8:v2.3.0-46 *
Red Hat Migration Toolkit for Containers 1.7 RedHat rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 *
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream *
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream *
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream *
Red Hat OpenShift Container Platform 4.8 RedHat openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream *
Red Hat OpenShift Jaeger 1.20 RedHat distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18 *
Red Hat OpenShift Jaeger 1.20 RedHat distributed-tracing/jaeger-query-rhel8:1.20.4-18 *
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 RedHat cockpit-ovirt-0:0.15.1-2.el8ev *
Red Hat Virtualization Engine 4.4 RedHat ovirt-engine-ui-extensions-0:1.2.6-1.el8ev *
Red Hat Virtualization Engine 4.4 RedHat ovirt-web-ui-0:1.6.9-1.el8ev *
Node-lodash Ubuntu bionic *
Node-lodash Ubuntu devel *
Node-lodash Ubuntu esm-apps/bionic *
Node-lodash Ubuntu esm-apps/focal *
Node-lodash Ubuntu esm-apps/jammy *
Node-lodash Ubuntu esm-apps/noble *
Node-lodash Ubuntu focal *
Node-lodash Ubuntu groovy *
Node-lodash Ubuntu hirsute *
Node-lodash Ubuntu impish *
Node-lodash Ubuntu jammy *
Node-lodash Ubuntu kinetic *
Node-lodash Ubuntu lunar *
Node-lodash Ubuntu mantic *
Node-lodash Ubuntu noble *
Node-lodash Ubuntu oracular *
Node-lodash Ubuntu trusty *
Node-lodash Ubuntu xenial *

References