CVE Watchtower

← Back to CVE List

CVE-2021-23337NVD

Vulnerability Summary

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Severity Level
HIGH(7.2)
Published Date
Feb 15, 2021
Last Modified
Oct 8, 2026
PoC
Available(Nuclei)
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
21.33%Probability
Root Weakness (CWE)
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended syntax or behavior.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Lodash Lodash < 4.17.21
  • Oracle Banking Corporate Lending Process Management
  • Oracle Banking Credit Facilities Process Management
  • Oracle Banking Extensibility Workbench
  • Oracle Banking Supply Chain Finance
  • Oracle Banking Trade Finance Process Management
  • Oracle Communications Cloud Native Core Binding Support Function
  • Oracle Communications Cloud Native Core Policy
  • Oracle Communications Design Studio
  • Oracle Communications Services Gatekeeper
  • Oracle Communications Session Border Controller
  • Oracle Enterprise Communications Broker
  • Oracle Financial Services Crime And Compliance Management Studio
  • Oracle Health Sciences Data Management Workbench
  • Oracle Jd Edwards Enterpriseone Tools < 9.2.6.1
  • Oracle Peoplesoft Enterprise Peopletools
  • Oracle Primavera Gateway >= 17.12.0 and <= 17.12.11
  • Oracle Primavera Gateway >= 18.8.0 and <= 18.8.12
  • Oracle Primavera Gateway >= 19.12.0 and <= 19.12.11
  • Oracle Primavera Gateway >= 20.12.0 and <= 20.12.7
  • Oracle Primavera Unifier >= 17.7 and <= 17.12
  • Oracle Primavera Unifier
  • Oracle Retail Customer Management And Segmentation Foundation
  • Netapp Active Iq Unified Manager
  • Netapp Cloud Manager
  • Netapp System Manager
  • Siemens Sinec Ins < 1.0
  • Siemens Sinec Ins
Patched Versions
  • Lodash Lodash 4.17.21
  • Oracle Jd Edwards Enterpriseone Tools 9.2.6.1
  • Siemens Sinec Ins 1.0
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.

External References