CVE-2021-23337: Command Injection
lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Other sources
A flaw was found in nodejs-lodash. A command injection flaw is possible through template variables.
All versions of package lodash; all versions of package org.fujion.webjars:lodash are vulnerable to Command Injection via template.
Reference: https://snyk.io/vuln/SNYK-JS-LODASH-1040724
— Red Hat
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/cockpit-ovirtto a version that resolves this vulnerability.Fixed in 0:0.15.1-2.el8e - Upgrade
Upgrade
redhat/ovirt-engine-ui-extensionsto a version that resolves this vulnerability.Fixed in 0:1.2.6-1.el8e - Upgrade
Upgrade
redhat/ovirt-web-uito a version that resolves this vulnerability.Fixed in 0:1.6.9-1.el8e - Upgrade
Upgrade
npm/lodash-esto a version that resolves this vulnerability.Fixed in 4.17.21 - Upgrade
Upgrade
npm/lodashto a version that resolves this vulnerability.Fixed in 4.17.21 - Upgrade
Upgrade
redhat/nodejs-lodashto a version that resolves this vulnerability.Fixed in 4.17.21 - Upgrade
Upgrade
rubygems/lodash-railsto a version that resolves this vulnerability.Fixed in 4.17.21 - Upgrade
Upgrade
debian/node-lodashto a version that resolves this vulnerability.Fixed in 4.17.21+dfsg+~cs8.31.173-1Fixed in 4.17.21+dfsg+~cs8.31.198.20210220-9Fixed in 4.18.1+dfsg-3 - Upgrade
Upgrade
lodashto a version that resolves this vulnerability.Fixed in 4.17.21 - Upgrade
Upgrade
org.fujion.webjars:lodashto a version that resolves this vulnerability.Fixed in 4.17.21
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-23337?
CVE-2021-23337 is a vulnerability in Lodash versions prior to 4.17.21 that allows command injection via the template function.
How does CVE-2021-23337 impact Node.js lodash module?
CVE-2021-23337 can allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection flaw in the template.
Which software is affected by CVE-2021-23337?
Node.js lodash module versions prior to 4.17.21 are affected by CVE-2021-23337.
What is the severity of CVE-2021-23337?
CVE-2021-23337 has a severity rating of high.
How can I fix the CVE-2021-23337 vulnerability?
To fix the CVE-2021-23337 vulnerability, update Node.js lodash module to version 4.17.21 or later.