The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
{ "binaries": [ { "binary_name": "libjs-underscore", "binary_version": "1.4.4-2ubuntu1+esm1" }, { "binary_name": "node-underscore", "binary_version": "1.4.4-2ubuntu1+esm1" } ], "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro" }
{ "binaries": [ { "binary_name": "libjs-underscore", "binary_version": "1.7.0~dfsg-1ubuntu1.1" }, { "binary_name": "node-underscore", "binary_version": "1.7.0~dfsg-1ubuntu1.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libjs-underscore", "binary_version": "1.8.3~dfsg-1ubuntu0.1" }, { "binary_name": "node-underscore", "binary_version": "1.8.3~dfsg-1ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "libjs-underscore", "binary_version": "1.9.1~dfsg-1ubuntu0.20.04.1" }, { "binary_name": "node-underscore", "binary_version": "1.9.1~dfsg-1ubuntu0.20.04.1" } ], "availability": "No subscription required" }