ZeroHour

CVE-2021-23337

PoC ×6
CVSS 3.1
7.2 high
EPSS
21%p97
Published
()
Modified
Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

Vendors
lodashoraclenetappsiemens
Products
lodash, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking supply chain finance, banking trade finance process management, communications cloud native core binding support function, communications cloud native core policy, communications design studio, communications services gatekeeper, communications session border controller, enterprise communications broker
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.