CVE-2021-23358
published 2021-03-29CVE-2021-23358: The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function…
PriorityP349high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
4.09%
89.7th percentile
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | underscore | < underscore 1.9.1~dfsg-2 (bookworm) | underscore 1.9.1~dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| tenable | tenable.sc | <= 5.18.0 | — |
| underscorejs | underscore | >= 0 < 1.9.1~dfsg-2 | 1.9.1~dfsg-2 |
| underscorejs | underscore | >= 0 < 1.9.1~dfsg-2 | 1.9.1~dfsg-2 |
| underscorejs | underscore | >= 0 < 1.9.1~dfsg-2 | 1.9.1~dfsg-2 |
| underscorejs | underscore | >= 0 < 1.9.1~dfsg-2 | 1.9.1~dfsg-2 |
| underscorejs | underscore | >= 1.13.0-0 < unspecified | unspecified |
| underscorejs | underscore | >= 1.13.0-0 < 1.13.0-2 | 1.13.0-2 |
| underscorejs | underscore | >= 1.3.2 < unspecified | unspecified |
| underscorejs | underscore | >= 1.3.2 < 1.12.1 | 1.12.1 |
| underscorejs | underscore | >= 1.3.2 < 1.12.1 | 1.12.1 |
| underscorejs | underscore | >= unspecified < 1.13.0-2 | 1.13.0-2 |
| underscorejs | underscore | >= unspecified < 1.12.1 | 1.12.1 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv7.2HIGH
vendor_oracle7.2LOW
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Arbitrary Code Execution in underscore
osv·2021-05-06
CVE-2021-23358 [CRITICAL] Arbitrary Code Execution in underscore
Arbitrary Code Execution in underscore
The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
GHSA
Arbitrary Code Execution in underscore
ghsa·2021-05-06
CVE-2021-23358 [CRITICAL] CWE-94 Arbitrary Code Execution in underscore
Arbitrary Code Execution in underscore
The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
OSV
CVE-2021-23358: The package underscore from 1
osv·2021-03-29·CVSS 7.2
CVE-2021-23358 [HIGH] CVE-2021-23358: The package underscore from 1
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Oracle
Oracle Oracle Commerce Risk Matrix: Business Control Center (underscore) — CVE-2021-23358
vendor_oracle·2024-10-15·CVSS 7.2
CVE-2021-23358 [LOW] Oracle Oracle Commerce Risk Matrix: Business Control Center (underscore) — CVE-2021-23358
Oracle Oracle Commerce Risk Matrix: Business Control Center (underscore) vulnerability
CVE: CVE-2021-23358
CVSS: 7.2
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: User Interface (UnderscoreJS) — CVE-2021-23358
vendor_oracle·2023-01-15·CVSS 3.3
CVE-2021-23358 [LOW] Oracle Oracle Construction and Engineering Risk Matrix: User Interface (UnderscoreJS) — CVE-2021-23358
Oracle Oracle Construction and Engineering Risk Matrix: User Interface (UnderscoreJS) vulnerability
CVE: CVE-2021-23358
CVSS: 3.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Ubuntu
Underscore vulnerability
vendor_ubuntu·2021-04-28
CVE-2021-23358 Underscore vulnerability
Title: Underscore vulnerability
Summary: Underscore could be made to inject arbitrary code if it received a specially
crafted input.
USN-4913-1 fixed vulnerabilities in Underscore. This update provides
the corresponding updates for Ubuntu 21.04.
Original advisory details:
It was discovered that Underscore incorrectly handled certain inputs.
An attacker could possibly use this issue to inject arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Underscore vulnerability
vendor_ubuntu·2021-04-14
CVE-2021-23358 Underscore vulnerability
Title: Underscore vulnerability
Summary: Underscore could be made to inject arbitrary code if it received a specially
crafted input.
It was discovered that Underscore incorrectly handled certain inputs.
An attacker could possibly use this issue to inject arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nodejs-underscore: Arbitrary code execution via the template function
vendor_redhat·2021-03-29·CVSS 3.3
CVE-2021-23358 [LOW] CWE-94 nodejs-underscore: Arbitrary code execution via the template function
nodejs-underscore: Arbitrary code execution via the template function
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
A flaw was found in nodejs-underscore. Arbitrary code execution via the template function is possible, particularly when a variable property is passed as an argument as it is not sanitized. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Whilst the OpenShift Container Platform (OCP) openshift4/ose-grafana and openshift3/grafana as well as console, grc-ui and search-ui containers for Red Hat Advanced M
Microsoft
Arbitrary Code Injection
vendor_msrc·2021-03-09·CVSS 3.3
CVE-2021-23358 [LOW] CWE-94 Arbitrary Code Injection
Arbitrary Code Injection
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
snyk: snyk
Customer Action Required: Yes
Debian
CVE-2021-23358: underscore - The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before ...
vendor_debian·2021·CVSS 3.3
CVE-2021-23358 [LOW] CVE-2021-23358: underscore - The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before ...
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Scope: local
bookworm: resolved (fixed in 1.9.1~dfsg-2)
bullseye: resolved (fixed in 1.9.1~dfsg-2)
forky: resolved (fixed in 1.9.1~dfsg-2)
sid: resolved (fixed in 1.9.1~dfsg-2)
trixie: resolved (fixed in 1.9.1~dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jashkenas/underscore/blob/master/modules/template.js%23L71https://lists.apache.org/thread.html/r5df90c46f7000c4aab246e947f62361ecfb849c5a553dcdb0ef545e1%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/r770f910653772317b117ab4472b0a32c266ee4abbafda28b8a6f9306%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/raae088abdfa4fbd84e1d19d7a7ffe52bf8e426b83e6599ea9a734dba%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/rbc84926bacd377503a3f5c37b923c1931f9d343754488d94e6f08039%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/re69ee408b3983b43e9c4a82a9a17cbbf8681bb91a4b61b46f365aeaf%40%3Cissues.cordova.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00038.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKATXXETD2PF3OR36Q5PD2VSVAR6J5Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FGEE7U4Z655A2MK5EW4UQQZ7B64XJWBV/https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1081503https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984https://www.debian.org/security/2021/dsa-4883https://www.tenable.com/security/tns-2021-14http://seclists.org/fulldisclosure/2025/Apr/14https://github.com/jashkenas/underscore/blob/master/modules/template.js%23L71https://lists.apache.org/thread.html/r5df90c46f7000c4aab246e947f62361ecfb849c5a553dcdb0ef545e1%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/r770f910653772317b117ab4472b0a32c266ee4abbafda28b8a6f9306%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/raae088abdfa4fbd84e1d19d7a7ffe52bf8e426b83e6599ea9a734dba%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/rbc84926bacd377503a3f5c37b923c1931f9d343754488d94e6f08039%40%3Cissues.cordova.apache.org%3Ehttps://lists.apache.org/thread.html/re69ee408b3983b43e9c4a82a9a17cbbf8681bb91a4b61b46f365aeaf%40%3Cissues.cordova.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/03/msg00038.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOKATXXETD2PF3OR36Q5PD2VSVAR6J5Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FGEE7U4Z655A2MK5EW4UQQZ7B64XJWBV/https://security.netapp.com/advisory/ntap-20240808-0003/https://security.netapp.com/advisory/ntap-20241108-0002/https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1081503https://snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984https://www.debian.org/security/2021/dsa-4883https://www.tenable.com/security/tns-2021-14
2021-03-29
Published