Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-23358

Опубликовано: 29 мар. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.5
CVSS3: 3.3

Описание

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

РелизСтатусПримечание
bionic

released

1.8.3~dfsg-1ubuntu0.1
devel

released

1.9.1~dfsg-2
esm-infra-legacy/trusty

released

1.4.4-2ubuntu1+esm1
esm-infra/bionic

released

1.8.3~dfsg-1ubuntu0.1
esm-infra/focal

released

1.9.1~dfsg-1ubuntu0.20.04.1
esm-infra/xenial

released

1.7.0~dfsg-1ubuntu1.1
focal

released

1.9.1~dfsg-1ubuntu0.20.04.1
groovy

released

1.9.1~dfsg-1ubuntu0.20.10.1
hirsute

released

1.9.1~dfsg-1ubuntu0.21.04.1
precise/esm

ignored

Показывать по

EPSS

Процентиль: 80%
0.01433
Низкий

6.5 Medium

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.2
redhat
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

CVSS3: 3.3
nvd
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

msrc
5 месяцев назад

Arbitrary Code Injection

CVSS3: 3.3
debian
почти 5 лет назад

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 a ...

suse-cvrf
почти 5 лет назад

Security update for nodejs-underscore

EPSS

Процентиль: 80%
0.01433
Низкий

6.5 Medium

CVSS2

3.3 Low

CVSS3