Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8p5q-j9m2-g8wr

Опубликовано: 03 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Withdrawn: Arbitrary code execution in lodash

Withdrawn

GitHub has chosen to publish this CVE as a withdrawn advisory due to it not being a security issue. See this issue for more details.

CVE description

"** DISPUTED ** A command injection vulnerability in Lodash 4.17.21 allows attackers to achieve arbitrary code execution via the template function. This is a different parameter, method, and version than CVE-2021-23337. NOTE: the vendor's position is that it's the developer's responsibility to ensure that a template does not evaluate code that originates from untrusted input.

Пакеты

Наименование

lodash

npm
Затронутые версииВерсия исправления

<= 4.17.21

Отсутствует

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

ubuntu
больше 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

nvd
больше 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

9.8 Critical

CVSS3

Дефекты

CWE-77