Prototype polution in Lodash - CVE-2020-8203

 

Prototype polution in Lodash - CVE-2020-8203

Published: August 10, 2020 / Updated: August 20, 2020


Vulnerability identifier: #VU41989
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8203
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when using _.zipObjectDeep in lodash. A remote attacker can inject and execute arbitrary script code.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

Lodash
Oracle Communications Subscriber-Aware Load Balancer
Oracle Communications Session Router
UCV – UrbanCode Velocity
IBM Intelligent Operations Center
IBM Tivoli Netcool/OMNIbus WebGUI
Bitbucket Data Center
Jira Service Management Server
Jira Software Data Center
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
IBM Process Mining
Use Case Manager App
Engineering Workflow Management
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Oracle Blockchain Platform
Oracle Communications Session Border Controller
Oracle Enterprise Communications Broker
IBM Watson Machine Learning Accelerator
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
Storage Defender – Data Protect
QRadar Assistant
MobileFirst Platform
cockpit-ovirt (Red Hat package)
v2v-conversion-host (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
node-lodash (Ubuntu package)
QRadar Pulse App
Oracle Banking Liquidity Management
Red Hat Virtualization Host
Red Hat Virtualization
OpenShift Virtualization
Oracle Communications Billing and Revenue Management
Bitbucket Server
Primavera Gateway
Jira Software Server
IBM InfoSphere Information Server
Ubuntu
IBM Cloud Pak System
Engineering Lifecycle Management

How to mitigate CVE-2020-8203

Install update from vendor's website.

Lodash - update to 4.17.16
cockpit-ovirt (Red Hat package) - update to 0.14.15-1.el8ev
UCV – UrbanCode Velocity - update to 2.4.0
QRadar Pulse App - update to 2.2.9
v2v-conversion-host (Red Hat package) - update to 1.16.2-8.el8ev
IBM Watson Machine Learning Accelerator - update to 2.3.4
redhat-release-virtualization-host (Red Hat package) - update to 4.4.3-2.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.4.3-20201210.0.el8_3
IBM Intelligent Operations Center - update to 5.2.4
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Jira Software Server - addressed in versions 10.3.12, 11.1.0
Jira Service Management Server - addressed in versions 10.3.12, 11.1.0
Jira Software Data Center - addressed in versions 10.3.12, 11.1.0
Jira Service Management Data Center - addressed in versions 10.3.12, 11.1.0
DevOps Test Performance - update to 11.0.8
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Storage Defender – Data Protect - update to 1.3.0
IBM Process Mining - update to 1.12.0.4
IBM Cloud Pak System - update to 2.3.3.5
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
QRadar Assistant - update to 3.6.0
Use Case Manager App - update to 4.0.0
OpenShift Virtualization - update to 4.8.1
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
IBM Security Verify Governance - update to 10.0.1.0.5
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins