Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23358

Опубликовано: 29 мар. 2021
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

A flaw was found in nodejs-underscore. Arbitrary code execution via the template function is possible, particularly when a variable property is passed as an argument as it is not sanitized. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Whilst the OpenShift Container Platform (OCP) openshift4/ose-grafana and openshift3/grafana as well as console, grc-ui and search-ui containers for Red Hat Advanced Management for Kubernetes (RHACM) include the vulnerable underscore library, the access to it is protected by OpenShift OAuth. Additionally this library is used in openshift4/ose-grafana container only in Grafana End-to-End Test package. Therefore the impact by this flaw is reduced to Low and the affected OCP components are marked as "will not fix" at this time and to Moderate for the affected RHACM components. This might be fixed in a future release. Red Hat Enterprise Virtualization includes the vulnerable underscore library, however it is not parsing any untrusted data, therefore impact is reduced to Low. Below Red Hat products include the underscore dependency, but it is not used by the product and hence this issue has been rated as having a security impact of Low.

  • Red Hat Quay
  • Red Hat Gluster Storage 3
  • Red Hat OpenShift Container Storage 4
  • Red Hat Ceph Storage 3 and 4

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Affected
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat Enterprise Linux 7pki-coreWill not fix
Red Hat Enterprise Linux 8pki-core:10.6/pki-coreWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/grafanaWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaFix deferred
Red Hat Openshift Container Storage 4ocs4/mcg-core-rhel8Affected
Red Hat Quay 3quay/quay-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1944286nodejs-underscore: Arbitrary code execution via the template function

EPSS

Процентиль: 80%
0.01433
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

CVSS3: 3.3
nvd
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

msrc
5 месяцев назад

Arbitrary Code Injection

CVSS3: 3.3
debian
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 a ...

suse-cvrf
почти 5 лет назад

Security update for nodejs-underscore

EPSS

Процентиль: 80%
0.01433
Низкий

7.2 High

CVSS3