Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-23358
HistoryMar 29, 2021 - 2:15 p.m.

Code injection

2021-03-2914:15:00
PRIOn knowledge base
www.prio-n.com
4

7 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.4%

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

References