CVE-2020-28500: Lodash
Medium severity, CVSS 5.3. EPSS: 7.3% chance of exploitation in the next 30 days.
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Affected products
- Lodash Lodash: before 4.17.21 (fixed in 4.17.21)
- Oracle Banking Corporate Lending Process Management: version 14.2.0 only; version 14.3.0 only; version 14.5.0 only
- Oracle Banking Credit Facilities Process Management: version 14.2.0 only; version 14.3.0 only; version 14.5.0 only
- Oracle Banking Extensibility Workbench: version 14.2.0 only; version 14.3.0 only; version 14.5.0 only
- Oracle Banking Supply Chain Finance: version 14.2.0 only; version 14.3.0 only; version 14.5.0 only
- Oracle Banking Trade Finance Process Management: version 14.2.0 only; version 14.3.0 only; version 14.5.0 only
- Oracle Communications Cloud Native Core Policy: version 1.11.0 only
- Oracle Communications Design Studio: version 7.4.2 only
- Oracle Communications Services Gatekeeper: version 7.0 only
- Oracle Communications Session Border Controller: version 8.4 only; version 9.0 only
- Oracle Enterprise Communications Broker: version 3.2.0 only; version 3.3.0 only
- Oracle Financial Services Crime And Compliance Management Studio: version 8.0.8.2.0 only; version 8.0.8.3.0 only
- Oracle Health Sciences Data Management Workbench: version 2.5.2.1 only; version 3.0.0.0 only
- Oracle Jd Edwards Enterpriseone Tools: before 9.2.6.1 (fixed in 9.2.6.1)
- Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only; version 8.59 only
- Oracle Primavera Gateway: from 17.12.0, up to and including 17.12.11; from 18.8.0, up to and including 18.8.12; from 19.12.0, up to and including 19.12.11; from 20.12.0, up to and including 20.12.7
- Oracle Primavera Unifier: from 17.7, up to and including 17.12; version 18.8 only; version 19.12 only; version 20.12 only
- Oracle Retail Customer Management And Segmentation Foundation: version 19.0 only
- Siemens Sinec Ins: before 1.0 (fixed in 1.0); version 1.0 only
Published 2021-02-15. Last modified 2026-10-08.