CVE-2021-23337: Command Injection
lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Other sources
A flaw was found in nodejs-lodash. A command injection flaw is possible through template variables.
All versions of package lodash; all versions of package org.fujion.webjars:lodash are vulnerable to Command Injection via template.
Reference: https://snyk.io/vuln/SNYK-JS-LODASH-1040724
— Red Hat
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-23337?
CVE-2021-23337 is a vulnerability in Lodash versions prior to 4.17.21 that allows command injection via the template function.
How does CVE-2021-23337 impact Node.js lodash module?
CVE-2021-23337 can allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection flaw in the template.
Which software is affected by CVE-2021-23337?
Node.js lodash module versions prior to 4.17.21 are affected by CVE-2021-23337.
What is the severity of CVE-2021-23337?
CVE-2021-23337 has a severity rating of high.
How can I fix the CVE-2021-23337 vulnerability?
To fix the CVE-2021-23337 vulnerability, update Node.js lodash module to version 4.17.21 or later.