7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Affected (48)
Products: Lodash: Lodash · Oracle: Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Extensibility Workbench, Banking Supply Chain Finance, Banking Trade Finance Process Management, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Policy, Communications Design Studio, Communications Services Gatekeeper, Communications Session Border Controller, Enterprise Communications Broker, Financial Services Crime And Compliance Management Studio, Health Sciences Data Management Workbench, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Customer Management And Segmentation Foundation · Netapp: Active Iq Unified Manager, Cloud Manager, System Manager · +1 more
Show all products
Lodash: Lodash · Oracle: Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Extensibility Workbench, Banking Supply Chain Finance, Banking Trade Finance Process Management, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Policy, Communications Design Studio, Communications Services Gatekeeper, Communications Session Border Controller, Enterprise Communications Broker, Financial Services Crime And Compliance Management Studio, Health Sciences Data Management Workbench, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Customer Management And Segmentation Foundation · Netapp: Active Iq Unified Manager, Cloud Manager, System Manager · Siemens: Sinec Ins
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 14.2.0 | |
| Version 1.9.0 | |
| Version 1.11.0 | |
| Version 7.4.2.0.0 | |
| Version 7.0 | |
| Version 8.4 | |
| Version 3.2.0 | |
| Version 8.0.8.2.0 | |
| Version 2.5.2.1 | |
| Before 9.2.6.1 | |
| Version 8.58 | |
| From 17.12.0 to 17.12.11 | |
| From 17.7 to 17.12 | |
| Version 19.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| Version 9.0 |
References (26)
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
Broken Link
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.