Lucene search

K
nodejsAnonymousNODEJS:1674
HistoryMay 06, 2021 - 4:14 p.m.

Arbitrary Code Execution

2021-05-0616:14:45
Anonymous
www.npmjs.com
55

0.011 Low

EPSS

Percentile

84.4%

Overview

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Recommendation

Upgrade to versions 1.12.1 or 1.13.0-2 or later

References

CPENameOperatorVersion
underscorege1.3.2 <1.12.1