Server side template injection In underscore
Description
Arbitrary Code Execution in underscore
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.12.1 | ||
debian 11 | 1.9.1~dfsg-2 | ||
debian 13 | 1.9.1~dfsg-2 | ||
debian 14 | 1.9.1~dfsg-2 | ||
debian 12 | 1.9.1~dfsg-2 | ||
rpm rhel7 | - | - | |
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24.