CVE-2021-23337

Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.517

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
Vulnerabilities CVE-2021-23337 are fixed in Ruby-lodash-rails 4.17.21Windows
Multiple Vulnerabilities are affected in IBM Aspera Faspex 5.0.15Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.12.24Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 13.0.7.0Windows
Vulnerabilities CVE-2021-23337 are fixed in Ruby-lodash-rails for Linux 4.17.21Linux
Improper Control of Generation of Code (Code Injection) Vulnerability (CVE-2021-23337)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234