CVE-2020-8203 - CVE House
Back to Database
Status published High CVE-2020-8203

Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20....

Affected Vendor

Affected Software

lodash
Vulnerable Versions:
Not Fixed

Timeline

Official Publish: July 15th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)