The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2613-1 | underscore security update |
![]() |
DSA-4883-1 | underscore security update |
![]() |
EUVD-2021-1042 | The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized. |
![]() |
GHSA-cf4h-3jhx-xvhq | Arbitrary Code Execution in underscore |
![]() |
USN-4913-1 | Underscore vulnerability |
![]() |
USN-4913-2 | Underscore vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 18 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
Sun, 08 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el7 |
Thu, 29 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 19 Aug 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el8 |

Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-17T03:47:56.577Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23358

Updated: 2024-08-08T13:05:14.728Z

Status : Modified
Published: 2021-03-29T14:15:18.047
Modified: 2024-11-21T05:51:34.207
Link: CVE-2021-23358


No data.