7.4
CVE-2020-8203
- EPSS 5.21%
- Veröffentlicht 15.07.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:29
- Erkennungen
WordPress Core < 5.8.1 - LoDash Update
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Banking Corporate Lending Process Management Version 14.2.0
Oracle ≫ Banking Corporate Lending Process Management Version 14.3.0
Oracle ≫ Banking Corporate Lending Process Management Version 14.5.0
Oracle ≫ Banking Credit Facilities Process Management Version 14.2.0
Oracle ≫ Banking Credit Facilities Process Management Version 14.3.0
Oracle ≫ Banking Credit Facilities Process Management Version 14.5.0
Oracle ≫ Banking Extensibility Workbench Version 14.2.0
Oracle ≫ Banking Extensibility Workbench Version 14.3.0
Oracle ≫ Banking Extensibility Workbench Version 14.5.0
Oracle ≫ Banking Liquidity Management Version 14.2.0
Oracle ≫ Banking Liquidity Management Version 14.3.0
Oracle ≫ Banking Liquidity Management Version 14.5.0
Oracle ≫ Banking Supply Chain Finance Version 14.2.0
Oracle ≫ Banking Supply Chain Finance Version 14.3.0
Oracle ≫ Banking Supply Chain Finance Version 14.5.0
Oracle ≫ Banking Trade Finance Process Management Version 14.2.0
Oracle ≫ Banking Trade Finance Process Management Version 14.3.0
Oracle ≫ Banking Trade Finance Process Management Version 14.5.0
Oracle ≫ Banking Virtual Account Management Version 14.2.0
Oracle ≫ Banking Virtual Account Management Version 14.3.0
Oracle ≫ Banking Virtual Account Management Version 14.5.0
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Communications Billing And Revenue Management Version 7.5.0.23.0
Oracle ≫ Communications Billing And Revenue Management Version 12.0.0.3.0
Oracle ≫ Communications Cloud Native Core Policy Version 1.11.0
Oracle ≫ Communications Session Border Controller Version 8.4
Oracle ≫ Communications Session Border Controller Version 9.0
Oracle ≫ Communications Session Border Controller Version cz8.4
Oracle ≫ Communications Session Router Version cz8.4
Oracle ≫ Communications Subscriber-aware Load Balancer Version cz8.3
Oracle ≫ Communications Subscriber-aware Load Balancer Version cz8.4
Oracle ≫ Enterprise Communications Broker Version 3.2.0
Oracle ≫ Enterprise Communications Broker Version 3.3.0
Oracle ≫ Enterprise Communications Broker Version pcz3.3
Oracle ≫ Jd Edwards Enterpriseone Tools Version <= 9.2.6.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.11
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.12
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.11
Oracle ≫ Primavera Gateway Version >= 20.12.0 <= 20.12.7
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
[5.4, 5.4.7)
Version
[5.5, 5.5.6)
Version
[5.6, 5.6.5)
Version
[5.7, 5.7.3)
Version
[5.8, 5.8.1)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.21% | 0.914 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://github.com/lodash/lodash/issues/4874
https://hackerone.com/reports/712065
https://security.netapp.com/advisory/ntap-20200724-0006/
https://www.wordfence.com/threat-intel/vulnerabilities/id/51cd834e-1b18-4702-9c6c-db7f34f2c687