#VU51945 Code Injection in Underscore.js - CVE-2021-23358
Published: April 6, 2021
Underscore.js
Jeremy Ashkenas
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://github.com/jashkenas/underscore/blob/master/modules/template.js%23L71
- https://lists.debian.org/debian-lts-announce/2021/03/msg00038.html
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1081503
- https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984
- https://www.debian.org/security/2021/dsa-4883