StackRadar

CVE-2020-8203

High

Advisory

Published 15 Jul 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.4
base score, highest
EPSS
0.052
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
123
of 17,781 indexed, latest versions
Container images
120
deployed by those charts
Fix available
3 of 5
affected packages

Prototype Pollution in lodash

Carried by container images the latest versions of 123 of 17,781 indexed charts deploy, on 120 images.

Affected packageAffected versionsFixed inImages
lodashnpm3.10.0, 3.10.1, 4.17.2, 4.17.4+5 more4.17.1975
lodash.picknpm4.4.0no fix listed34
lodash.setnpm4.3.2no fix listed16
lodash-esnpm4.17.4, 4.17.154.17.2011
node-lodashdeb4.17.15+dfsg-24.17.15+dfsg-2ubuntu0.1~esm12
OSV records
GHSA-p6mc-m468-83gwUBUNTU-CVE-2020-8203
Also known as
USN-8411-1

Charts affected

123 by stars
ChartLatestAffected imagesRadar Score
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
lodash@3.10.1
4.17.19

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
lodash@3.10.1
4.17.19

Open the chart page →

36,215
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
lodash.pick@4.4.0
no fix listed

Open the chart page →

6,524
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
lodash@4.17.15
4.17.19

Open the chart page →

5,215
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
lodash.pick@4.4.0
no fix listed

Open the chart page →

4,684
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
lodash.pick@4.4.0
no fix listed

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
lodash.pick@4.4.0
no fix listed

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
lodash@4.17.4
lodash.pick@4.4.0
4.17.19
no fix listed

Open the chart page →

3,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
lodash@4.17.15
4.17.19

Open the chart page →

3,696
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
lodash@4.17.15
4.17.19

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
lodash@4.17.15
4.17.19

Open the chart page →

29,220
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
lodash@4.17.15
4.17.19

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
lodash@4.17.15
4.17.19

Open the chart page →

1,890
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
lodash@4.17.15
4.17.19

Open the chart page →

4,967
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
lodash@3.10.1
4.17.19

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
lodash@3.10.1
4.17.19

Open the chart page →

12,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
lodash@4.17.15
node-lodash@4.17.15+dfsg-2
4.17.19
4.17.15+dfsg-2ubuntu0.1~esm1

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
lodash@4.17.15
4.17.19

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
lodash@4.17.11
4.17.19

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
lodash@3.10.1
4.17.19

Open the chart page →

3,576
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
lodash.pick@4.4.0
no fix listed

Open the chart page →

3,118
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
lodash-es@4.17.15
4.17.20

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2020-8203.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
lodash-es@4.17.15
lodash.pick@4.4.0
4.17.20
no fix listed

Open the chart page →

5,806

Container images carrying it

120 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ibmcom/app-nav-init:1.0.1240ff499eb5b
lodash@3.10.1
4.17.19
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
lodash@3.10.1
4.17.19
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
lodash@4.17.10
4.17.19
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
lodash@4.17.10
4.17.19
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
lodash@4.17.5
4.17.19
1
ibmcom/microclimate-portal:latested5505e5c7ec
lodash@4.17.5
4.17.19
1
ibmcom/microclimate-theia:lateste17bdccc5030
lodash@3.10.1
4.17.19
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
lodash@4.17.15
4.17.19
1
inseefrlab/shelly:cloudshell31f04ca7436b
lodash@4.17.15
4.17.19
1
jayfong/yapi:1.10.2163e5d621910
lodash@4.17.15
4.17.19
1
konradkleine/docker-registry-frontend:v2181aad54ee64
lodash@3.10.1
4.17.19
1
koumoul/openapi-viewer:18eeca2e8285b
lodash@3.10.1
4.17.19
1
lavandadelpatio/frontend:latest501c3f31e0bc
lodash@4.17.15
4.17.19
1
library/ghost:6.37.01ef2e532ca4d
lodash.pick@4.4.0
no fix listed
1
library/ghost:6.25.12654b1e90413
lodash.pick@4.4.0
no fix listed
1
library/ghost:6.41.129773d6be407
lodash.pick@4.4.0
no fix listed
1
library/ghost:4.37.0767230c0f263
lodash.pick@4.4.0
no fix listed
1
library/ghost:6.39.0-alpine77196da4b0df
lodash.pick@4.4.0
no fix listed
1
library/ghost:5.79.083f7bf209844
lodash.pick@4.4.0
no fix listed
1
library/ghost:6.62.0a7a268bbfb7f
lodash.pick@4.4.0
no fix listed
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
lodash.pick@4.4.0
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
lodash.pick@4.4.0
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
lodash@4.17.15
node-lodash@4.17.15+dfsg-2
4.17.19
4.17.15+dfsg-2ubuntu0.1~esm1
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
lodash@3.10.1
4.17.19
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
lodash@4.17.2
4.17.19
1
minddocdev/hubot:0.1.96c60b11a4fa7
lodash@4.17.11
4.17.19
1
misskey/misskey:12.110.1e08b7c478093
lodash.pick@4.4.0
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
lodash@3.10.1
4.17.19
1
n8nio/n8n:0.212.0a9195bc499a3
lodash.pick@4.4.0
lodash.set@4.3.2
no fix listed
no fix listed
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
lodash@4.17.15
4.17.19
1
nodered/node-red-docker:0.19.6-v8070643219ea2
lodash.pick@4.4.0
no fix listed
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
lodash.pick@4.4.0
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
lodash@3.10.1
4.17.19
1
ondrejsika/parking:latestb1fd497416c8
lodash@4.17.15
4.17.19
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
lodash@3.10.1
4.17.19
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
lodash@4.17.15
4.17.19
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
lodash@4.17.11
4.17.19
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
lodash.set@4.3.2
no fix listed
1
phntom/codimd:2.4.31b9aafbb62e6
lodash.pick@4.4.0
no fix listed
1
polonel/trudesk:1.2.60cf6513f6fe3
lodash@4.17.11
4.17.19
1
roadiehq/community-backstage-image:latestef355bf5b639
lodash@4.17.15
lodash-es@4.17.15
4.17.19
4.17.20
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
lodash@3.10.1
4.17.19
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
lodash@4.17.15
4.17.19
1
someblackmagic/alert-mapper:v0.1.088351d85c04c
lodash@4.17.15
4.17.19
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
lodash.set@4.3.2
no fix listed
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
lodash@4.17.15
node-lodash@4.17.15+dfsg-2
4.17.19
4.17.15+dfsg-2ubuntu0.1~esm1
1
temporalio/web:1.14.033cfa863d8ce
lodash-es@4.17.15
4.17.20
1
testhubio/testhub-frontend:on-preme86c2db53be8
lodash@4.17.15
4.17.19
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
lodash@4.17.4
4.17.19
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
lodash.set@4.3.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.