HIGH · 7.2

CVE-2021-23337

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Vulnerability Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LodashLodash< 4.17.21
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Extensibility Workbench14.2.0
OracleBanking Supply Chain Finance14.2.0
OracleBanking Trade Finance Process Management14.2.0
OracleCommunications Cloud Native Core Binding Support Function1.9.0
OracleCommunications Cloud Native Core Policy1.11.0
OracleCommunications Design Studio7.4.2.0.0
OracleCommunications Services Gatekeeper7.0
OracleCommunications Session Border Controller8.4
OracleEnterprise Communications Broker3.2.0
OracleFinancial Services Crime And Compliance Management Studio8.0.8.2.0
OracleHealth Sciences Data Management Workbench2.5.2.1
OracleJd Edwards Enterpriseone Tools< 9.2.6.1
OraclePeoplesoft Enterprise Peopletools8.58
OraclePrimavera Gateway>= 17.12.0, <= 17.12.11
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleRetail Customer Management And Segmentation Foundation19.0
NetappActive Iq Unified Manager-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23337?

CVE-2021-23337 is a vulnerability with a CVSS score of 7.2 (HIGH). Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

How severe is CVE-2021-23337?

CVE-2021-23337 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23337?

Check the references section above for vendor advisories and patch information. Affected products include: Lodash Lodash, Oracle Banking Corporate Lending Process Management, Oracle Banking Credit Facilities Process Management, Oracle Banking Extensibility Workbench, Oracle Banking Supply Chain Finance.