CVE-2021-23358
29.03.2021, 14:15
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Vendor | Product | Version |
---|---|---|
underscorejs | underscore | 1.3.2 ≤ 𝑥 < 1.12.1 |
underscorejs | underscore | 1.13.0-0 ≤ 𝑥 < 1.13.0-2 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
tenable | tenable.sc | 𝑥 ≤ 5.18.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References