CVE-2021-23358
29.03.2021, 14:15
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
| Vendor | Product | Version |
|---|---|---|
| underscorejs | underscore | 1.3.2 ≤ 𝑥 < 1.12.1 |
| underscorejs | underscore | 1.13.0-0 ≤ 𝑥 < 1.13.0-2 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| tenable | tenable.sc | 𝑥 ≤ 5.18.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References