CVE Vulnerabilities

CVE-2020-28500

Published: Feb 15, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

Affected Software

NameVendorStart VersionEnd Version
LodashLodash*4.17.21 (excluding)
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/application-ui-rhel8:v2.3.0-120*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/console-api-rhel8:v2.3.0-63*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/kui-web-terminal-rhel8:v2.3.0-51*
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8RedHatrhacm2/search-api-rhel8:v2.3.0-46*
Red Hat Migration Toolkit for Containers 1.7RedHatrhmtc/openshift-migration-ui-rhel8:v1.7.4-12*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream*
Red Hat OpenShift Container Platform 4.8RedHatopenshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream*
Red Hat OpenShift Jaeger 1.20RedHatdistributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18*
Red Hat OpenShift Jaeger 1.20RedHatdistributed-tracing/jaeger-query-rhel8:1.20.4-18*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatcockpit-ovirt-0:0.15.1-2.el8ev*
Red Hat Virtualization Engine 4.4RedHatovirt-engine-ui-extensions-0:1.2.6-1.el8ev*
Red Hat Virtualization Engine 4.4RedHatovirt-web-ui-0:1.6.9-1.el8ev*
Node-lodashUbuntubionic*
Node-lodashUbuntudevel*
Node-lodashUbuntuesm-apps/bionic*
Node-lodashUbuntuesm-apps/focal*
Node-lodashUbuntuesm-apps/jammy*
Node-lodashUbuntuesm-apps/noble*
Node-lodashUbuntufocal*
Node-lodashUbuntugroovy*
Node-lodashUbuntuhirsute*
Node-lodashUbuntuimpish*
Node-lodashUbuntujammy*
Node-lodashUbuntukinetic*
Node-lodashUbuntulunar*
Node-lodashUbuntumantic*
Node-lodashUbuntunoble*
Node-lodashUbuntuoracular*
Node-lodashUbuntuplucky*
Node-lodashUbuntuquesting*
Node-lodashUbuntutrusty*
Node-lodashUbuntuxenial*

References