The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 18 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
ssvc
|
Sun, 08 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el7 |
Thu, 29 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 19 Aug 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el8 |
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2021-03-29T13:15:34.770665Z
Updated: 2024-09-17T03:47:56.577Z
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23358
Vulnrichment
Updated: 2024-08-08T13:05:14.728Z
NVD
Status : Modified
Published: 2021-03-29T14:15:18.047
Modified: 2024-11-21T05:51:34.207
Link: CVE-2021-23358
Redhat