CVE-2021-23358
LOWUnderscore < 1.12.1 - Code Injection
Title source: ruleDescription
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Exploits (2)
nomisec
SCANNER
2 stars
by EkamSinghWalia · poc
https://github.com/EkamSinghWalia/Detection-script-for-cve-2021-23358
nomisec
WORKING POC
1 stars
by MehdiBoukhobza · poc
https://github.com/MehdiBoukhobza/SandBox_CVE-2021-23358
References (18)
Scores
CVSS v3
3.3
EPSS
0.0108
EPSS Percentile
77.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-94
Status
published
Products (7)
debian/debian_linux
9.0
debian/debian_linux
10.0
fedoraproject/fedora
33
fedoraproject/fedora
34
npm/underscore
1.3.2 - 1.12.1npm
tenable/tenable.sc
< 5.18.0
underscorejs/underscore
1.3.2 - 1.12.1
Published
Mar 29, 2021
Tracked Since
Feb 18, 2026