Title: CVE-2020-8203 @ Npm-lodash-4.17.11 · Issue #50 · DefenderForCodeOrg/msft · GitHub
Open Graph Title: CVE-2020-8203 @ Npm-lodash-4.17.11 · Issue #50 · DefenderForCodeOrg/msft
X Title: CVE-2020-8203 @ Npm-lodash-4.17.11 · Issue #50 · DefenderForCodeOrg/msft
Description: Vulnerable Package issue exists @ Npm-lodash-4.17.11 in branch main Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. Namespace: James-AST Repository: msft Repository Url: https://github.com/James-AST/msft C...
Open Graph Description: Vulnerable Package issue exists @ Npm-lodash-4.17.11 in branch main Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. Namespace: James-AST Repository: msft Repository ...
X Description: Vulnerable Package issue exists @ Npm-lodash-4.17.11 in branch main Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. Namespace: James-AST Repository: msft Repository ...
Opengraph URL: https://github.com/DefenderForCodeOrg/msft/issues/50
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"CVE-2020-8203 @ Npm-lodash-4.17.11","articleBody":"**Vulnerable Package** issue exists @ **Npm\\-lodash\\-4\\.17\\.11** in branch **main**\r\n\r\nPrototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.\r\n\r\n**Namespace:** James-AST\r\n**Repository:** msft\r\n**Repository Url:** https://github.com/James-AST/msft\r\n**CxAST\\-Project:** James-AST/msft\r\n**CxAST platform scan:** [d217bf9e\\-499c\\-4ae8\\-a115\\-08b6cd62b182](https://ast.checkmarx.net/projects/fada48c7-0c49-472a-994a-763d8a847895/scans?id=d217bf9e-499c-4ae8-a115-08b6cd62b182\u0026branch=main)\r\n**Branch:** main\r\n**Application:** msft\r\n**Severity:** HIGH\r\n**State:** NOT_IGNORED\r\n**Status:** RECURRENT\r\n**CWE:** CWE-1321\r\n\r\n\r\n----\r\n**Addition Info**\r\n**Attack vector:** NETWORK\r\n**Attack complexity:** HIGH\r\n**Confidentiality impact:** NONE\r\n**Availability impact:** HIGH\r\n**Remediation Upgrade Recommendation:** 4.17.21\r\n\r\n\r\n----\r\n**References**\r\n[Advisory](https://github.com/advisories/GHSA-p6mc-m468-83gw)\r\n[Pull request](https://github.com/lodash/lodash/pull/4759)\r\n[Commit](https://github.com/lodash/lodash/commit/c84fe82760fb2d3e03a63379b297a1cc1a2fce12)\r\n[Disclosure](https://hackerone.com/reports/712065)\r\n","author":{"url":"https://github.com/jbrotsos","@type":"Person","name":"jbrotsos"},"datePublished":"2022-06-16T16:40:04.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/50/msft/issues/50"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:9986bb4a-84a5-26ad-b121-5561a25feecb |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 89DE:1E1EE3:258FE87:322F917:6A5D8377 |
| html-safe-nonce | 9834faa6c9f7831f713c7dde7966a753f49e2acee3adbfa029c45b69d10808a4 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI4OURFOjFFMUVFMzoyNThGRTg3OjMyMkY5MTc6NkE1RDgzNzciLCJ2aXNpdG9yX2lkIjoiODczODE4NzA5Mzc5MTgzNDk5OSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 22ef6ba6e677e127ef1f6638ecba13f7ee9aefacc8d373d39865720ea0b5b7f8 |
| hovercard-subject-tag | issue:1273823086 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/DefenderForCodeOrg/msft/50/issue_layout |
| twitter:image | https://opengraph.githubassets.com/e1f6df002a699bb7162349100aaeacd03844590a20f441e4401e74ef875c1560/DefenderForCodeOrg/msft/issues/50 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/e1f6df002a699bb7162349100aaeacd03844590a20f441e4401e74ef875c1560/DefenderForCodeOrg/msft/issues/50 |
| og:image:alt | Vulnerable Package issue exists @ Npm-lodash-4.17.11 in branch main Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. Namespace: James-AST Repository: msft Repository ... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | jbrotsos |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5290d7e14309ad1e76106a9c4237bd1041517e83ea182c8ab756752cb0c6940b |
| turbo-cache-control | no-preview |
| go-import | github.com/DefenderForCodeOrg/msft git https://github.com/DefenderForCodeOrg/msft.git |
| octolytics-dimension-user_id | 83890223 |
| octolytics-dimension-user_login | DefenderForCodeOrg |
| octolytics-dimension-repository_id | 504225335 |
| octolytics-dimension-repository_nwo | DefenderForCodeOrg/msft |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 504225335 |
| octolytics-dimension-repository_network_root_nwo | DefenderForCodeOrg/msft |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 9c975978430e9ad293956f2bbdaf153b1bd84a99 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width