CVE-2021-23358

Published: 29 March 2021

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Priority

Medium

CVSS 3 base score: 7.2

Status

Package Release Status
underscore
Launchpad, Ubuntu, Debian
Upstream
Released (1.9.1~dfsg-2)
Ubuntu 21.04 (Hirsute Hippo)
Released (1.9.1~dfsg-1ubuntu0.21.04.1)
Ubuntu 20.10 (Groovy Gorilla)
Released (1.9.1~dfsg-1ubuntu0.20.10.1)
Ubuntu 20.04 LTS (Focal Fossa)
Released (1.9.1~dfsg-1ubuntu0.20.04.1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (1.8.3~dfsg-1ubuntu0.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (1.7.0~dfsg-1ubuntu1.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (1.4.4-2ubuntu1+esm1)