Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-4800

4 месяца назад

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-r5fr-rjxr-66jc

4 месяца назад

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-19167

около 1 месяца назад

ELSA-2026-19167: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-19008

15 дней назад

ELSA-2026-19008: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10713

3 месяца назад

ELSA-2026-10713: pcs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10710

3 месяца назад

ELSA-2026-10710: pcs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-09406

4 месяца назад

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
EPSS: Низкий
rocky логотип

RLSA-2026:24331

около 2 месяцев назад

Important: cockpit-image-builder security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24331

16 дней назад

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
redhat логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
nvd логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.

CVSS3: 8.1
3%
Низкий
4 месяца назад
debian логотип
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...

CVSS3: 8.1
3%
Низкий
4 месяца назад
github логотип
GHSA-r5fr-rjxr-66jc

lodash vulnerable to Code Injection via `_.template` imports key names

CVSS3: 8.1
3%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-19167

ELSA-2026-19167: pcs security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-19008

ELSA-2026-19008: pcs security update (IMPORTANT)

15 дней назад
oracle-oval логотип
ELSA-2026-10713

ELSA-2026-10713: pcs security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-10710

ELSA-2026-10710: pcs security update (IMPORTANT)

3 месяца назад
fstec логотип
BDU:2026-09406

Уязвимость библиотеки Lodash, связанная с неверным управлением генерацией кода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
3%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:24331

Important: cockpit-image-builder security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24331

ELSA-2026-24331: cockpit-image-builder security update (IMPORTANT)

16 дней назад

Уязвимостей на страницу