nodejs-lodash: prototype pollution in zipObjectDeep function
Published Jul 15, 2020
7.4
HIGHCVSS 3.1
EPSS 5.21%
Description
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Affected products
- Vendor n/a Product Lodash Defaultn/a
- Version Not FixedStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Lodash | n/a |
|
Configuration 2
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- < 21.1.2
- 7.5.0.23.0
- 12.0.0.3.0
- 1.11.0
- 8.4
- 9.0
- cz8.4
- cz8.4
- cz8.3
- cz8.4
- 3.2.0
- 3.3.0
- pcz3.3
- ≤ 9.2.6.0
- 8.58
- 8.59
- ≥ 17.12.0 · ≤ 17.12.11
- ≥ 18.8.0 · ≤ 18.8.12
- ≥ 19.12.0 · ≤ 19.12.11
- ≥ 20.12.0 · ≤ 20.12.7
No data.
Jaeger-1.17
distributed-tracing/jaeger-agent-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-collector-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-ingester-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-query-rhel7:1.17.6-1
Fixed · RHSA-2020:3370
Jaeger-1.17
distributed-tracing/jaeger-rhel7-operator:1.17.6-1
Fixed · RHSA-2020:3370
OpenShift Service Mesh 1.1
ior-0:1.1.6-1.el8
Fixed · RHSA-2020:3369
OpenShift Service Mesh 1.1
servicemesh-0:1.1.6-1.el8
Fixed · RHSA-2020:3369
OpenShift Service Mesh 1.1
servicemesh-cni-0:1.1.6-1.el8
Fixed · RHSA-2020:3369
OpenShift Service Mesh 1.1
servicemesh-grafana-0:6.4.3-13.el8
Fixed · RHSA-2020:3369
OpenShift Service Mesh 1.1
servicemesh-operator-0:1.1.6-2.el8
Fixed · RHSA-2020:3369
OpenShift Service Mesh 1.1
servicemesh-prometheus-0:2.14.0-14.el8
Fixed · RHSA-2020:3369
Openshift Service Mesh 1.1
kiali-0:v1.12.10.redhat2-1.el7
Fixed · RHSA-2020:3369
Red Hat OpenShift Container Platform 4.6
openshift4/ose-metering-presto:v4.6.0-202010200139.p0
Fixed · RHSA-2020:4298
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
cockpit-ovirt-0:0.14.15-1.el8ev
Fixed · RHSA-2020:5611
Red Hat Virtualization Engine 4.4
org.ovirt.engine-root-0:4.4.3.8-1
Fixed · RHSA-2020:5179
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.3-1.el8ev
Fixed · RHSA-2020:3807
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.6.4-1.el8ev
Fixed · RHSA-2020:3807
OpenShift Service Mesh 1
jaeger
Out of support scope
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Fix deferred
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
logging-kibana5-container
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-jenkins-agent-nodejs
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hadoop
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Fix deferred
Red Hat Virtualization 4
ovirt-engine-api-explorer
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Jaeger-1.17 | distributed-tracing/jaeger-agent-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-collector-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-ingester-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-query-rhel7:1.17.6-1 | Fixed | RHSA-2020:3370 |
| Jaeger-1.17 | distributed-tracing/jaeger-rhel7-operator:1.17.6-1 | Fixed | RHSA-2020:3370 |
| OpenShift Service Mesh 1.1 | ior-0:1.1.6-1.el8 | Fixed | RHSA-2020:3369 |
| OpenShift Service Mesh 1.1 | servicemesh-0:1.1.6-1.el8 | Fixed | RHSA-2020:3369 |
| OpenShift Service Mesh 1.1 | servicemesh-cni-0:1.1.6-1.el8 | Fixed | RHSA-2020:3369 |
| OpenShift Service Mesh 1.1 | servicemesh-grafana-0:6.4.3-13.el8 | Fixed | RHSA-2020:3369 |
| OpenShift Service Mesh 1.1 | servicemesh-operator-0:1.1.6-2.el8 | Fixed | RHSA-2020:3369 |
| OpenShift Service Mesh 1.1 | servicemesh-prometheus-0:2.14.0-14.el8 | Fixed | RHSA-2020:3369 |
| Openshift Service Mesh 1.1 | kiali-0:v1.12.10.redhat2-1.el7 | Fixed | RHSA-2020:3369 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-metering-presto:v4.6.0-202010200139.p0 | Fixed | RHSA-2020:4298 |
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | cockpit-ovirt-0:0.14.15-1.el8ev | Fixed | RHSA-2020:5611 |
| Red Hat Virtualization Engine 4.4 | org.ovirt.engine-root-0:4.4.3.8-1 | Fixed | RHSA-2020:5179 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.3-1.el8ev | Fixed | RHSA-2020:3807 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.6.4-1.el8ev | Fixed | RHSA-2020:3807 |
| OpenShift Service Mesh 1 | jaeger | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | logging-kibana5-container | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-jenkins-agent-nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Fix deferred | n/a |
| Red Hat Virtualization 4 | ovirt-engine-api-explorer | Affected | n/a |
lodash.update
npm
Introduced 0 Fixed not fixedlodash.updatewith
npm
Introduced 0 Fixed not fixedlodash-rails
RubyGems
Introduced 3.7.0 Fixed 4.17.19lodash
npm
Introduced 3.7.0 Fixed 4.17.19lodash-es
npm
Introduced 3.7.0 Fixed 4.17.20lodash.pick
npm
Introduced 4.0.0 Fixed not fixedlodash.set
npm
Introduced 3.7.0 Fixed not fixedlodash.setwith
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | lodash.update | 0 | not fixed |
| npm | lodash.updatewith | 0 | not fixed |
| RubyGems | lodash-rails | 3.7.0 | 4.17.19 |
| npm | lodash | 3.7.0 | 4.17.19 |
| npm | lodash-es | 3.7.0 | 4.17.20 |
| npm | lodash.pick | 4.0.0 | not fixed |
| npm | lodash.set | 3.7.0 | not fixed |
| npm | lodash.setwith | 0 | not fixed |
Remediation
Red Hat statement
In OpenShift ServiceMesh (OSSM), Red Hat OpenShift Jaeger (RHOSJ) and Red Hat OpenShift Container Platform (RHOCP), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-lodash library is used, but due to the code changing to the container first content the kibana package is marked as wontfix. This may be fixed in the future. Red Hat Virtualization uses vulnerable version of nodejs-lodash, however zipObjectDeep is not used, therefore the impact is low.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (33 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.21% (0.05213) | 92.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.21% (0.05213) | 91.40th | v5 (v2026.06.15) |
| May 26, 2026 | 2.55% (0.02546) | 85.67th | v4 (v2025.03.14) |
| Mar 24, 2026 | 3.57% (0.03570) | 87.61th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.98% (0.01978) | 83.38th | v4 (v2025.03.14) |
| Feb 9, 2026 | 3.31% (0.03306) | 86.93th | v4 (v2025.03.14) |
| Feb 1, 2026 | 2.09% (0.02087) | 83.69th | v4 (v2025.03.14) |
| Jan 4, 2026 | 3.51% (0.03510) | 87.26th | v4 (v2025.03.14) |
| Jan 1, 2026 | 2.14% (0.02144) | 83.83th | v4 (v2025.03.14) |
| Dec 18, 2025 | 4.42% (0.04423) | 88.64th | v4 (v2025.03.14) |
| Dec 4, 2025 | 3.36% (0.03364) | 86.92th | v4 (v2025.03.14) |
| Dec 1, 2025 | 2.05% (0.02053) | 83.39th | v4 (v2025.03.14) |
| Nov 19, 2025 | 3.28% (0.03276) | 85.95th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.59% (0.05586) | 89.35th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.44% (0.02439) | 83.74th | v4 (v2025.03.14) |
| Mar 29, 2025 | 25.84% (0.25839) | 93.97th | v4 (v2025.03.14) |
| Mar 24, 2025 | 2.44% (0.02439) | 83.68th | v4 (v2025.03.14) |
| Mar 23, 2025 | 16.51% (0.16508) | 94.04th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.44% (0.02439) | 84.07th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.65% (0.01645) | 88.08th | v3 (v2023.03.01) |
| Jun 21, 2024 | 1.67% (0.01667) | 87.73th | v3 (v2023.03.01) |
| Jun 5, 2024 | 1.46% (0.01463) | 86.38th | v3 (v2023.03.01) |
| Sep 3, 2023 | 1.04% (0.01036) | 82.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.95% (0.00954) | 80.85th | v3 (v2023.03.01) |
| Mar 6, 2023 | 19.17% (0.19173) | 96.36th | v2 (v2022.01.01) |
| Apr 20, 2022 | 19.17% (0.19173) | 96.05th | v2 (v2022.01.01) |
| Apr 19, 2022 | 14.86% (0.14862) | 95.55th | v2 (v2022.01.01) |
| Feb 8, 2022 | 14.86% (0.14862) | 91.29th | v2 (v2022.01.01) |
| Feb 4, 2022 | 8.93% (0.08934) | 82.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Oct 21, 2021 | 6.21% (0.06208) | 89.85th | v5 (v2026.06.15) |
| Jun 15, 2021 | 4.50% (0.04504) | 0.00th | v1 |
| Apr 14, 2021 | 3.63% (0.03630) | 0.00th | v1 |
References (21)
- https://access.redhat.com/security/cve/CVE-2020-8203 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1857412 Issue Tracking
- https://github.com/advisories/GHSA-p6mc-m468-83gw Advisory
- https://github.com/github/advisory-database/pull/2884
- https://github.com/lodash/lodash/commit/c84fe82760fb2d3e03a63379b297a1cc1a2fce12
- https://github.com/lodash/lodash/issues/4744
- https://github.com/lodash/lodash/issues/4874 x_refsource_MISCIssue TrackingVendor Advisory
- https://github.com/lodash/lodash/wiki/Changelog#v41719
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-8203.yml
- https://hackerone.com/reports/712065 x_refsource_MISCExploitThird Party Advisory
- https://hackerone.com/reports/864701
- https://nvd.nist.gov/vuln/detail/CVE-2020-8203
- https://security.netapp.com/advisory/ntap-20200724-0006 x_refsource_CONFIRMThird Party Advisory
- https://web.archive.org/web/20210914001339/https://github.com/lodash/lodash/issues/4744
- https://www.cve.org/CVERecord?id=CVE-2020-8203
- https://www.npmjs.com/advisories/1523
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.