Command Injection in Lodash - CVE-2021-23337

 

Command Injection in Lodash - CVE-2021-23337

Published: May 12, 2021


Vulnerability identifier: #VU53202
CSH Severity: Medium
CVSS v4 BT: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-23337
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the system.

The vulnerability exists due to improper input validation when processing templates. A remote privileged user can inject and execute arbitrary commands on the system.


Affected software

Lodash
IBM VM Recovery Manager HA GUI
IBM VM Recovery Manager DR
Storage Defender Copy Data Management
IBM Watson Machine Learning Accelerator
DataStage on Cloud Pak for Data
Maximo Application Suite - Monitor Component
Rational Performance Tester
DevOps Test Performance
InfoSphere Optim Archive Viewer
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Business Automation Insights
Storage Defender – Data Protect
QRadar Assistant
MobileFirst Platform
Maximo Scheduler Optimizer
cockpit-ovirt (Red Hat package)
ovirt-hosted-engine-ha (Red Hat package)
node-lodash (Ubuntu package)
ovirt-hosted-engine-setup (Red Hat package)
ovirt-host (Red Hat package)
vdsm (Red Hat package)
QRadar Pulse App
Cloudera Data Platform Private Cloud Base for IBM
Oracle Financial Services Crime and Compliance Management Studio
semantic-release
Red Hat OpenShift Jaeger
UCV – UrbanCode Velocity
Oracle Communications Cloud Native Core Binding Support Function
IBM Cloud Transformation Advisor
IBM Security Guardium Insights
Oracle Health Sciences Data Management Workbench
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Automation Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Intelligent Operations Center
Oracle Communications Design Studio
IBM Tivoli Netcool/OMNIbus WebGUI
Bitbucket Data Center
IBM Cloud Pak for Business Automation
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
Use Case Manager App
IBM Watson Assistant for IBM Cloud Pak for Data
Engineering Workflow Management
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
Migration Toolkit for Containers
IBM Edge Application Manager
Primavera Unifier
JD Edwards EnterpriseOne Tools
Cloud Pak for Security (CP4S)
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Virtualization Host
WordPress
Oracle Communications Services Gatekeeper
Bitbucket Server
Primavera Gateway
PeopleSoft Enterprise PeopleTools
IBM InfoSphere Information Server
IBM App Connect Enterprise
Engineering Lifecycle Management
Ubuntu
Oracle Retail Customer Management and Segmentation Foundation
IBM Security SOAR
IBM Security QRadar Analyst Workflow
SINEC INS
IBM Cloud Pak System

How to mitigate CVE-2021-23337

Install updates from vendor's website.

Lodash - update to 4.17.21
cockpit-ovirt (Red Hat package) - update to 0.15.1-2.el8ev
QRadar Pulse App - update to 2.2.9
semantic-release - update to 17.4.3
UCV – UrbanCode Velocity - update to 2.4.0
Migration Toolkit for Containers - update to 1.7.4
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - update to 1.20.4
Storage Defender Copy Data Management - update to 2.3.0.1
IBM Watson Machine Learning Accelerator - update to 2.3.4
ovirt-hosted-engine-ha (Red Hat package) - update to 2.4.8-1.el8ev
IBM Security Guardium Insights - update to 3.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
IBM Intelligent Operations Center - update to 5.2.4
WordPress - addressed in versions 5.2.12, 5.4.7, 5.5.6, 5.6.5, 5.7.3, 5.8.1
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.8
Maximo Application Suite - Monitor Component - addressed in versions 8.10.29, 8.11.27, 9.0.19, 9.1.9
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
DevOps Test Performance - update to 11.0.8
InfoSphere Optim Archive Viewer - update to 11.7.0.14
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM App Connect Enterprise - addressed in versions 12.0.12.25, 13.0.7.1
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
Primavera Gateway - addressed in versions 18.8.13, 19.12.12, 20.12.8
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Security SOAR - update to 51.0.10.0
SINEC INS - update to 1.0 SP2
Storage Defender – Data Protect - update to 1.3.0
IBM Process Mining - update to 1.12.0.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.2
IBM Cloud Pak System - update to 2.3.3.5
node-lodash (Ubuntu package) - addressed in versions 2.4.1+dfsg-3ubuntu0.1~esm1, 4.17.4+dfsg-1ubuntu0.1~esm1, 4.17.15+dfsg-2ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-5ubuntu0.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.24.04.1~esm1, 4.17.21+dfsg+~cs8.31.198.20210220-9ubuntu0.25.10.1, 4.17.23+dfsg-1ubuntu0.1~esm1
ovirt-hosted-engine-setup (Red Hat package) - update to 2.5.3-1.el8ev
IBM Security QRadar Analyst Workflow - update to 2.15.1
QRadar Assistant - update to 3.6.0
Use Case Manager App - update to 4.0.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
ovirt-host (Red Hat package) - update to 4.4.8-2.el8ev
vdsm (Red Hat package) - update to 4.40.80.5-1.el8ev
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
Engineering Workflow Management - addressed in versions 7.0.1 iFix021, 7.0.2 iFix021
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
JD Edwards EnterpriseOne Tools - update to 9.2.6.1
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins