Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cf4h-3jhx-xvhq

Опубликовано: 06 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Arbitrary Code Execution in underscore

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Ссылки

Пакеты

Наименование

underscore

npm
Затронутые версииВерсия исправления

>= 1.3.2, < 1.12.1

1.12.1

EPSS

Процентиль: 80%
0.01433
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

CVSS3: 7.2
redhat
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

CVSS3: 3.3
nvd
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

msrc
5 месяцев назад

Arbitrary Code Injection

CVSS3: 3.3
debian
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 a ...

EPSS

Процентиль: 80%
0.01433
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94