Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-4800

6 месяцев назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-4800

6 месяцев назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-4800

6 месяцев назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-4800

6 месяцев назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-r5fr-rjxr-66jc

6 месяцев назад

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19167

3 месяца назад

ELSA-2026-19167: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19008

около 2 месяцев назад

ELSA-2026-19008: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10713

5 месяцев назад

ELSA-2026-10713: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10710

5 месяцев назад

ELSA-2026-10710: pcs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09406

6 месяцев назад

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:24331

3 месяца назад

Important: cockpit-image-builder security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24331

2 месяца назад

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
6 месяцев назад
debian логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
3%
Низкий
6 месяцев назад
github логотип
GHSA-r5fr-rjxr-66jc

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
3%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2026-19167

ELSA-2026-19167: pcs security update (IMPORTANT)

3%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-19008

ELSA-2026-19008: pcs security update (IMPORTANT)

3%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-10713

ELSA-2026-10713: pcs security update (IMPORTANT)

3%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-10710

ELSA-2026-10710: pcs security update (IMPORTANT)

3%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-09406

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
3%
Низкий
6 месяцев назад
rocky логотип
RLSA-2026:24331

Important: cockpit-image-builder security update

3 месяца назад
oracle-oval логотип
ELSA-2026-24331

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

2 месяца назад

Уязвимостей на страницу