Underscorejs Underscore 1.12.0 for Node.js

CPE Details

Underscorejs Underscore 1.12.0 for Node.js
1.12.0
2021-03-30
11h06 +00:00
2021-03-31
11h18 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:underscorejs:underscore:1.12.0:*:*:*:*:node.js:*:*

Informations

Vendor

underscorejs

Product

underscore

Version

1.12.0

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-23358 2021-03-29 13h15 +00:00 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
7.2
High