Code Injection in Underscore.js - CVE-2021-23358
Published: April 6, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
rhv-log-collector-analyzer (Red Hat package)
ovirt-engine-ui-extensions (Red Hat package)
ovirt-engine-extension-aaa-ldap (Red Hat package)
vdsm-jsonrpc-java (Red Hat package)
ovirt-web-ui (Red Hat package)
ovirt-engine-dwh (Red Hat package)
ovirt-engine (Red Hat package)
ovirt-log-collector (Red Hat package)
rhvm-branding-rhv (Red Hat package)
node-underscore (Ubuntu package)
libjs-underscore (Ubuntu package)
underscore (Debian package)
nodejs-underscore
js-underscore
unboundid-ldapsdk (Red Hat package)
Red Hat Advanced Cluster Management for Kubernetes
Tenable Nessus
Bitbucket Data Center
IBM Cloud Pak for Business Automation
Netcool Operations Insight
Red Hat Virtualization Manager
Tenable.sc
IBM App Connect Enterprise
Oracle Commerce Platform
Ubuntu
openEuler
Fedora
Primavera Unifier
Business Automation Insights
IBM Cloud Pak for Watson AIOps
MobileFirst Platform
IBM InfoSphere Information Server
How to mitigate CVE-2021-23358
rhv-log-collector-analyzer (Red Hat package) - addressed in versions 1.0.10-1.el8ev, 1.0.15-1.el8ev
ovirt-engine-ui-extensions (Red Hat package) - addressed in versions 1.2.7-1.el8ev, 1.3.5-1.el8ev
ovirt-engine-extension-aaa-ldap (Red Hat package) - addressed in versions 1.4.4-1.el8ev, 1.4.6-1.el8ev
vdsm-jsonrpc-java (Red Hat package) - update to 1.7.2-1.el8ev
ovirt-web-ui (Red Hat package) - addressed in versions 1.7.0-1.el8ev, 1.9.1-1.el8ev
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.0.10, 2.2.3
ovirt-engine-dwh (Red Hat package) - addressed in versions 4.4.7.3-1.el8ev, 4.5.4-1.el8ev
ovirt-engine (Red Hat package) - addressed in versions 4.4.7.6-0.11.el8ev, 4.5.2.4-0.1.el8ev
ovirt-log-collector (Red Hat package) - update to 4.4.7-2.el8ev
rhvm-branding-rhv (Red Hat package) - update to 4.4.9-1.el8ev
Tenable.sc - update to 5.19.0
Tenable Nessus - update to 10.1.0
Bitbucket Data Center - update to 10.3.2
IBM App Connect Enterprise - update to 11.0.0.13
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Netcool Operations Insight - update to 1.6.6
node-underscore (Ubuntu package) - addressed in versions 1.7.0~dfsg-1ubuntu1.1, 1.8.3~dfsg-1ubuntu0.1, 1.9.1~dfsg-1ubuntu0.20.04.1, 1.9.1~dfsg-1ubuntu0.20.10.1, 1.9.1~dfsg-1ubuntu0.21.04.1
libjs-underscore (Ubuntu package) - addressed in versions 1.7.0~dfsg-1ubuntu1.1, 1.8.3~dfsg-1ubuntu0.1, 1.9.1~dfsg-1ubuntu0.20.04.1, 1.9.1~dfsg-1ubuntu0.20.10.1, 1.9.1~dfsg-1ubuntu0.21.04.1
underscore (Debian package) - update to 1.9.1~dfsg-1+deb10u1
nodejs-underscore - update to 1.9.1-2
js-underscore - update to 1.9.1-2
nodejs-underscore - addressed in versions 1.13.1-1.fc33, 1.13.1-1.fc34
IBM Cloud Pak for Watson AIOps - update to 3.5
unboundid-ldapsdk (Red Hat package) - update to 6.0.4-1.el8ev
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
- https://github.com/jashkenas/underscore/blob/master/modules/template.js%23L71
- https://lists.debian.org/debian-lts-announce/2021/03/msg00038.html
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1081503
- https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984
- https://www.debian.org/security/2021/dsa-4883
Related Security Bulletins
- Remote code execution in Underscore
- Debian update for underscore
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Red Hat Virtualization Manager
- Tenable Nessus update for Underscore.js
- Ubuntu update for underscore
- Ubuntu update for underscore
- Multiple vulnerabilities in Red Hat Virtualization Manager
- Remote code execution in IBM App connect Enterprise
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOPs
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in IBM InfoSphere Information Server
- openEuler 20.03 LTS SP1 update for nodejs-underscore
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation
- Multiple vulnerabilities in Oracle Commerce Platform
- Fedora 34 update for nodejs-underscore
- Fedora 33 update for nodejs-underscore
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Bitbucket Data Center