OESA-2021-1174
Dashboard / Vulnerabilities / OESA-2021-1174
Summary: nodejs-underscore security update
Details: Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects. Security Fix(es): The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.(CVE-2021-23358)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1174, https://nvd.nist.gov/vuln/detail/CVE-2021-23358
Affected packages
Package
Name: nodejs-underscore
Purl: pkg:rpm/openEuler/nodejs-underscore&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
