← Back to CVE List
CVE-2021-23337NVD
Vulnerability Summary
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Lodash Lodash < 4.17.21
- Oracle Banking Corporate Lending Process Management
- Oracle Banking Credit Facilities Process Management
- Oracle Banking Extensibility Workbench
- Oracle Banking Supply Chain Finance
- Oracle Banking Trade Finance Process Management
- Oracle Communications Cloud Native Core Binding Support Function
- Oracle Communications Cloud Native Core Policy
- Oracle Communications Design Studio
- Oracle Communications Services Gatekeeper
- Oracle Communications Session Border Controller
- Oracle Enterprise Communications Broker
- Oracle Financial Services Crime And Compliance Management Studio
- Oracle Health Sciences Data Management Workbench
- Oracle Jd Edwards Enterpriseone Tools < 9.2.6.1
- Oracle Peoplesoft Enterprise Peopletools
- Oracle Primavera Gateway >= 17.12.0 and <= 17.12.11
- Oracle Primavera Gateway >= 18.8.0 and <= 18.8.12
- Oracle Primavera Gateway >= 19.12.0 and <= 19.12.11
- Oracle Primavera Gateway >= 20.12.0 and <= 20.12.7
- Oracle Primavera Unifier >= 17.7 and <= 17.12
- Oracle Primavera Unifier
- Oracle Retail Customer Management And Segmentation Foundation
- Netapp Active Iq Unified Manager
- Netapp Cloud Manager
- Netapp System Manager
- Siemens Sinec Ins < 1.0
- Siemens Sinec Ins
- Lodash Lodash 4.17.21
- Oracle Jd Edwards Enterpriseone Tools 9.2.6.1
- Siemens Sinec Ins 1.0
External References
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851
- https://security.netapp.com/advisory/ntap-20210312-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851
- https://security.netapp.com/advisory/ntap-20210312-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html