Regular Expression Denial of Service (ReDoS)
Published Feb 15, 2021
5.3
MEDIUMCVSS 3.1
EPSS 7.34%
Description
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Affected products
- Vendor n/a Product Lodash Defaultn/a
- Version versions prior to 4.17.21StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Lodash | n/a |
|
Configuration 2
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 1.11.0
- 7.4.2
- 7.0
- 8.4
- 9.0
- 3.2.0
- 3.3.0
- 8.0.8.2.0
- 8.0.8.3.0
- 2.5.2.1
- 3.0.0.0
- < 9.2.6.1
- 8.58
- 8.59
- ≥ 17.12.0 · ≤ 17.12.11
- ≥ 18.8.0 · ≤ 18.8.12
- ≥ 19.12.0 · ≤ 19.12.11
- ≥ 20.12.0 · ≤ 20.12.7
- ≥ 17.7 · ≤ 17.12
- 18.8
- 19.12
- 20.12
- 19.0
No data.
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.4-12
Fixed · RHSA-2022:6429
Red Hat OpenShift Container Platform 4.8
openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Jaeger 1.20
distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18
Fixed · RHSA-2021:2543
Red Hat OpenShift Jaeger 1.20
distributed-tracing/jaeger-query-rhel8:1.20.4-18
Fixed · RHSA-2021:2543
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
cockpit-ovirt-0:0.15.1-2.el8ev
Fixed · RHSA-2021:3459
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.6-1.el8ev
Fixed · RHSA-2021:2179
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.6.9-1.el8ev
Fixed · RHSA-2021:2179
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
application-ui
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
console-api
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
console-header
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
console-ui
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
grc-ui
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
grc-ui-api
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
kui-web-terminal
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
mcm-topology
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
mcm-topology-api
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
search-api
Affected
Red Hat Ansible Automation Platform 1.2
lodash
Not affected
Red Hat Decision Manager 7
lodash
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 4
golang-github-prometheus-promu
Affected
Red Hat OpenShift Container Platform 4
kibana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hadoop
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-presto
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel9
Affected
Red Hat OpenShift Container Platform 4
rhel8/grafana
Affected
Red Hat Process Automation 7
lodash
Not affected
Red Hat Quay 3
quay
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | Fixed | RHSA-2022:6429 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Jaeger 1.20 | distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18 | Fixed | RHSA-2021:2543 |
| Red Hat OpenShift Jaeger 1.20 | distributed-tracing/jaeger-query-rhel8:1.20.4-18 | Fixed | RHSA-2021:2543 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | cockpit-ovirt-0:0.15.1-2.el8ev | Fixed | RHSA-2021:3459 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.6-1.el8ev | Fixed | RHSA-2021:2179 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.6.9-1.el8ev | Fixed | RHSA-2021:2179 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | application-ui | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | console-api | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | console-header | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | console-ui | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | grc-ui | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | grc-ui-api | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | kui-web-terminal | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | mcm-topology | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | mcm-topology-api | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | search-api | Affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | lodash | Not affected | n/a |
| Red Hat Decision Manager 7 | lodash | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | golang-github-prometheus-promu | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-presto | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | rhel8/grafana | Affected | n/a |
| Red Hat Process Automation 7 | lodash | Not affected | n/a |
| Red Hat Quay 3 | quay | Will not fix | n/a |
lodash-es
npm
Introduced 4.0.0 Fixed 4.17.21lodash.trimend
npm
Introduced 4.0.0 Fixed not fixedlodash.trim
npm
Introduced 4.0.0 Fixed not fixedlodash-rails
RubyGems
Introduced 4.0.0 Fixed 4.17.21lodash
npm
Introduced 4.0.0 Fixed 4.17.21
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | lodash-es | 4.0.0 | 4.17.21 |
| npm | lodash.trimend | 4.0.0 | not fixed |
| npm | lodash.trim | 4.0.0 | not fixed |
| RubyGems | lodash-rails | 4.0.0 | 4.17.21 |
| npm | lodash | 4.0.0 | 4.17.21 |
Remediation
Red Hat statement
In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Jaeger (RHOSJ) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. While Red Hat Virtualization's cockpit-ovirt has a dependency on lodash it doesn't use the vulnerable toNumber, trim, or trimEnd functions. While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable toNumber, trim, or trimEnd functions.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 7.34% (0.07336) | 94.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.34% (0.07336) | 93.58th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.24% (0.00245) | 47.63th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.56% (0.03558) | 86.52th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.27% (0.00275) | 48.91th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.23% (0.00231) | 62.11th | v3 (v2023.03.01) |
| Nov 1, 2023 | 0.23% (0.00231) | 61.10th | v3 (v2023.03.01) |
| Sep 22, 2023 | 0.21% (0.00212) | 58.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00182) | 53.66th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Jul 26, 2022 | 2.69% (0.02686) | 81.86th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.31% (0.16306) | 92.84th | v2 (v2022.01.01) |
| Feb 3, 2022 | 12.44% (0.12435) | 88.79th | v1 |
| Jan 6, 2022 | 12.44% (0.12435) | 88.65th | v1 |
| Oct 21, 2021 | 3.07% (0.03068) | 81.33th | v1 |
| Sep 1, 2021 | 2.82% (0.02818) | 80.51th | v1 |
| Jul 21, 2021 | 2.82% (0.02818) | 0.00th | v1 |
| Apr 14, 2021 | 2.57% (0.02567) | 0.00th | v1 |
References (23)
- https://access.redhat.com/security/cve/CVE-2020-28500 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1928954 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/advisories/GHSA-29mw-wpgm-hmr9 Advisory
- https://github.com/github/advisory-database/pull/6139
- https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8 x_refsource_MISCBroken Link
- https://github.com/lodash/lodash/commit/c4847ebe7d14540bb28a8b932a9ce1b9ecbfee1a
- https://github.com/lodash/lodash/pull/5065 x_refsource_MISCPatchThird Party Advisory
- https://github.com/lodash/lodash/pull/5065/commits/02906b8191d3c100c193fe6f7b27d1c40f200bb7
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-28500.yml
- https://nvd.nist.gov/vuln/detail/CVE-2020-28500
- https://security.netapp.com/advisory/ntap-20210312-0006 x_refsource_CONFIRMThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-28500
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCNot ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.