Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lodash
Subscribe
|
Lodash
Subscribe
|
|
Netapp
Subscribe
|
|
|
Oracle
Subscribe
|
Banking Corporate Lending Process Management
Subscribe
Banking Credit Facilities Process Management
Subscribe
Banking Extensibility Workbench
Subscribe
Banking Supply Chain Finance
Subscribe
Banking Trade Finance Process Management
Subscribe
Communications Cloud Native Core Binding Support Function
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Design Studio
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Session Border Controller
Subscribe
Enterprise Communications Broker
Subscribe
Financial Services Crime And Compliance Management Studio
Subscribe
Health Sciences Data Management Workbench
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Primavera Gateway
Subscribe
Primavera Unifier
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
|
|
Redhat
Subscribe
|
|
|
Siemens
Subscribe
|
Sinec Ins
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0912 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
Github GHSA |
GHSA-35jh-r3h4-6jhm | Command Injection in lodash |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el7 |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el8 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T19:15:17.074Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23337
No data.
Status : Modified
Published: 2021-02-15T13:15:12.560
Modified: 2024-11-21T05:51:31.643
Link: CVE-2021-23337
OpenCVE Enrichment
No data.
EUVD
Github GHSA