← Back

CVE-2021-23337

Published: Feb 15, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Affected (48)

Products: Lodash: Lodash · Oracle: Banking Corporate Lending Process Management, Banking Credit Facilities Process Management, Banking Extensibility Workbench, Banking Supply Chain Finance, Banking Trade Finance Process Management, Communications Cloud Native Core Binding Support Function, Communications Cloud Native Core Policy, Communications Design Studio, Communications Services Gatekeeper, Communications Session Border Controller, Enterprise Communications Broker, Financial Services Crime And Compliance Management Studio, Health Sciences Data Management Workbench, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Primavera Gateway, Primavera Unifier, Retail Customer Management And Segmentation Foundation · Netapp: Active Iq Unified Manager, Cloud Manager, System Manager · +1 more
Show all products
1 product
Lodash
18 products
3 products
Active Iq Unified Manager
Cloud Manager
System Manager
1 product
Sinec Ins
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.17.21
Configuration B
39 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Oracle
Version 14.2.0
Version 14.3.0
Version 14.5.0
Version 1.9.0
Version 1.11.0
Version 7.4.2.0.0
Version 7.0
Oracle
Version 8.4
Version 9.0
Oracle
Version 3.2.0
Version 3.3.0
Oracle
Version 8.0.8.2.0
Version 8.0.8.3.0
Oracle
Version 2.5.2.1
Version 3.0.0.0
Before 9.2.6.1
Oracle
Version 8.58
Version 8.59
Oracle
From 17.12.0 to 17.12.11
From 18.8.0 to 18.8.12
From 19.12.0 to 19.12.11
From 20.12.0 to 20.12.7
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Version 19.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
All versions
Version 9.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Before 1.0
Version 1.0
Version 1.0 sp1

References (26)

Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
Third Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
ExploitThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: report@snyk.io
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.