CVE-2021-23337
high · 7.2A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
7.2
CVSS
21.3%
EPSS (exploit prob.)
97th
EPSS percentile
2021-02-15
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| lodash | lodash | < 4.17.21 |
| oracle | banking_corporate_lending_process_management | 14.2.0 |
| oracle | banking_corporate_lending_process_management | 14.3.0 |
| oracle | banking_corporate_lending_process_management | 14.5.0 |
| oracle | banking_credit_facilities_process_management | 14.2.0 |
| oracle | banking_credit_facilities_process_management | 14.3.0 |
| oracle | banking_credit_facilities_process_management | 14.5.0 |
| oracle | banking_extensibility_workbench | 14.2.0 |
| oracle | banking_extensibility_workbench | 14.3.0 |
| oracle | banking_extensibility_workbench | 14.5.0 |
| oracle | banking_supply_chain_finance | 14.2.0 |
| oracle | banking_supply_chain_finance | 14.3.0 |
| oracle | banking_supply_chain_finance | 14.5.0 |
| oracle | banking_trade_finance_process_management | 14.2.0 |
| oracle | banking_trade_finance_process_management | 14.3.0 |
| oracle | banking_trade_finance_process_management | 14.5.0 |
| oracle | communications_cloud_native_core_binding_support_function | 1.9.0 |
| oracle | communications_cloud_native_core_policy | 1.11.0 |
| oracle | communications_design_studio | 7.4.2.0.0 |
| oracle | communications_services_gatekeeper | 7.0 |
| oracle | communications_session_border_controller | 8.4 |
| oracle | communications_session_border_controller | 9.0 |
| oracle | enterprise_communications_broker | 3.2.0 |
| oracle | enterprise_communications_broker | 3.3.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
| oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
| oracle | health_sciences_data_management_workbench | 2.5.2.1 |
| oracle | health_sciences_data_management_workbench | 3.0.0.0 |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.1 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| oracle | primavera_gateway | >= 17.12.0, <= 17.12.11 |
| oracle | primavera_gateway | >= 18.8.0, <= 18.8.12 |
| oracle | primavera_gateway | >= 19.12.0, <= 19.12.11 |
| oracle | primavera_gateway | >= 20.12.0, <= 20.12.7 |
| oracle | primavera_unifier | >= 17.7, <= 17.12 |
| oracle | primavera_unifier | 18.8 |
| oracle | primavera_unifier | 19.12 |
| oracle | primavera_unifier | 20.12 |
| oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
Check a specific version with /api/v1/cve/match.
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851
- https://security.netapp.com/advisory/ntap-20210312-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851
- https://security.netapp.com/advisory/ntap-20210312-0006/
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-23337