PT-2021-3188 · Lodash+1 · Lodash+1

Marc Hassan

·

Published

2021-02-15

·

Updated

2026-06-09

·

CVE-2021-23337

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lodash versions prior to 4.17.21
Description The issue is related to Command Injection via the template function, which can be exploited by a remote attacker to execute arbitrary commands. This is due to the lack of neutralization of special elements used in the operating system command.
Recommendations For versions prior to 4.17.21, update to version 4.17.21 or later to resolve the issue. As a temporary workaround, consider disabling the template function until a patch is available. Restrict access to the template function to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-44655
BDU:2021-02877
CVE-2021-23337
GHSA-35JH-R3H4-6JHM
RHSA-2021:2179
RHSA-2021:3459
SNYK-JAVA-ORGFUJIONWEBJARS-1074932
SNYK-JAVA-ORGWEBJARS-1074930
SNYK-JAVA-ORGWEBJARSBOWER-1074928
SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931
SNYK-JAVA-ORGWEBJARSNPM-1074929
SNYK-JS-LODASH-1040724
USN-8411-1

Affected Products

Bitbucket
Lodash