VDB

CVE-2020-28500

CVE-2020-28500 PUBLISHED CVSS 5.300000190734863 MEDIUM

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

EPSS 7.34% · 93.9th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
7.34%
93.9th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSnode-lodash4.17.11+dfsg-4, 0, 4.17.15+dfsg-2
Ubuntu:24.04:LTSnode-lodash4.17.21+dfsg+~cs8.31.198.20210220-9, 0
Ubuntu:18.04:LTSnode-lodash0, 4.17.4+dfsg-1
Ubuntu:25.10node-lodash*, 0
Oracle Cloudfunctions
Ubuntu:16.04:LTSnode-lodash0, 2.4.1+dfsg-3
Azurefunctions
Ubuntu:22.04:LTSnode-lodash0, 4.17.21+dfsg+~cs8.31.173-1, 4.17.21+dfsg+~cs8.31.198.20210220-4

Timeline

  • Feb 15, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 7, 2022 PoC Published
  • May 2, 2022 EPSS Score
  • Jul 26, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›