Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23337

Опубликовано: 15 фев. 2021
Источник: redhat
CVSS3: 7.2

Описание

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

A flaw was found in nodejs-lodash. A command injection flaw is possible through template variables.

Отчет

In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Jaeger (RHOSJ) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. While Red Hat Virtualization's cockpit-ovirt has a dependency on lodash it doesn't use the vulnerable template function. While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable template function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0kialiAffected
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-api-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-header-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-api-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-api-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1928937nodejs-lodash: command injection via template

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 5 лет назад

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

CVSS3: 7.2
nvd
почти 5 лет назад

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

CVSS3: 7.2
debian
почти 5 лет назад

Lodash versions prior to 4.17.21 are vulnerable to Command Injection v ...

CVSS3: 7.2
github
почти 5 лет назад

Command Injection in lodash

CVSS3: 7.2
fstec
больше 4 лет назад

Уязвимость библиотеки lodash прикладного программного обеспечения Аврора Центр, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольную команду

7.2 High

CVSS3