CVE-2021-23337

Source
https://cve.org/CVERecord?id=CVE-2021-23337
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-23337.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-23337
Aliases
Downstream
Related
  • SNYK-JAVA-ORGFUJIONWEBJARS-1074932
  • SNYK-JAVA-ORGWEBJARS-1074930
  • SNYK-JAVA-ORGWEBJARSBOWER-1074928
  • SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
  • SNYK-JAVA-ORGWEBJARSNPM-1074929
  • SNYK-JS-LODASH-1040724
Published
2021-02-15T13:15:12.560Z
Modified
2026-05-28T04:06:28.679555153Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "oracle:jd_edwards_enterpriseone_tools",
            "extracted_events": [
                {
                    "fixed": "9.2.6.1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:primavera_gateway",
            "extracted_events": [
                {
                    "introduced": "17.12.0"
                },
                {
                    "last_affected": "17.12.11"
                },
                {
                    "introduced": "18.8.0"
                },
                {
                    "last_affected": "18.8.12"
                },
                {
                    "introduced": "19.12.0"
                },
                {
                    "last_affected": "19.12.11"
                },
                {
                    "introduced": "20.12.0"
                },
                {
                    "last_affected": "20.12.7"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "oracle:primavera_unifier",
            "extracted_events": [
                {
                    "introduced": "17.7"
                },
                {
                    "last_affected": "17.12"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "siemens:sinec_ins",
            "extracted_events": [
                {
                    "fixed": "1.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE"
        },
        {
            "vendor_product": "netapp:system_manager",
            "extracted_events": [
                {
                    "last_affected": "9.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:netapp:system_manager:9.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:banking_corporate_lending_process_management",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:banking_credit_facilities_process_management",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:banking_extensibility_workbench",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:banking_supply_chain_finance",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:banking_trade_finance_process_management",
            "extracted_events": [
                {
                    "last_affected": "14.2.0"
                },
                {
                    "last_affected": "14.3.0"
                },
                {
                    "last_affected": "14.5.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_cloud_native_core_binding_support_function",
            "extracted_events": [
                {
                    "last_affected": "1.9.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.9.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_cloud_native_core_policy",
            "extracted_events": [
                {
                    "last_affected": "1.11.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.11.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_design_studio",
            "extracted_events": [
                {
                    "last_affected": "7.4.2.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_design_studio:7.4.2.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_services_gatekeeper",
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_services_gatekeeper:7.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:communications_session_border_controller",
            "extracted_events": [
                {
                    "last_affected": "8.4"
                },
                {
                    "last_affected": "9.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:communications_session_border_controller:8.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:communications_session_border_controller:9.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:enterprise_communications_broker",
            "extracted_events": [
                {
                    "last_affected": "3.2.0"
                },
                {
                    "last_affected": "3.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:enterprise_communications_broker:3.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:financial_services_crime_and_compliance_management_studio",
            "extracted_events": [
                {
                    "last_affected": "8.0.8.2.0"
                },
                {
                    "last_affected": "8.0.8.3.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.2.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:financial_services_crime_and_compliance_management_studio:8.0.8.3.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:health_sciences_data_management_workbench",
            "extracted_events": [
                {
                    "last_affected": "2.5.2.1"
                },
                {
                    "last_affected": "3.0.0.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:health_sciences_data_management_workbench:2.5.2.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:health_sciences_data_management_workbench:3.0.0.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:peoplesoft_enterprise_peopletools",
            "extracted_events": [
                {
                    "last_affected": "8.58"
                },
                {
                    "last_affected": "8.59"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:primavera_unifier",
            "extracted_events": [
                {
                    "last_affected": "18.8"
                },
                {
                    "last_affected": "19.12"
                },
                {
                    "last_affected": "20.12"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*",
                "cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "oracle:retail_customer_management_and_segmentation_foundation",
            "extracted_events": [
                {
                    "last_affected": "19.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        },
        {
            "vendor_product": "siemens:sinec_ins",
            "extracted_events": [
                {
                    "last_affected": "1.0-NA"
                },
                {
                    "last_affected": "1.0-sp1"
                }
            ],
            "cpes": [
                "cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/lodash/lodash

Affected ranges

Type
GIT
Repo
https://github.com/lodash/lodash
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.17.21"
        }
    ],
    "cpe": "cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*",
    "source": "CPE_RANGE"
}

Affected versions

3.*
3.0.0-npm
3.0.1-npm
3.1.0-npm
3.10.0-npm
3.10.1-npm
3.2.0-npm
3.3.0-npm
3.3.1-npm
3.4.0-npm
3.5.0-npm
3.6.0-npm
3.7.0-npm
3.8.0-npm
3.9.0-npm
3.9.1-npm
3.9.2-npm
3.9.3-npm
4.*
4.0.0-npm
4.0.1-npm
4.1.0-npm
4.10.0-npm
4.11.0-npm
4.11.1-npm
4.11.2-npm
4.12.0-npm
4.13.0-npm
4.13.1-npm
4.14.0-npm
4.14.1-npm
4.14.2-npm
4.15.0-npm
4.16.0-npm
4.16.1-npm
4.16.2-npm
4.16.3-npm
4.16.4-npm
4.16.5-npm
4.16.6-npm
4.17.0-npm
4.17.1-npm
4.17.10-npm
4.17.11-npm
4.17.12-npm
4.17.13-npm
4.17.14-npm
4.17.15-npm
4.17.2-npm
4.17.20-npm
4.17.3-npm
4.17.4-npm
4.17.5-npm
4.17.9-npm
4.2.0-npm
4.2.1-npm
4.3.0-npm
4.4.0-npm
4.5.0-npm
4.5.1-npm
4.6.0-npm
4.6.1-npm
4.7.0-npm
4.8.0-npm
4.8.1-npm
4.8.2-npm
4.9.0-npm

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-23337.json"