The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
| Software | From | Fixed in |
|---|---|---|
| underscorejs / underscore | 1.3.2 | 1.12.1 |
| underscorejs / underscore | 1.13.0-0 | 1.13.0-2 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| tenable / tenable.sc | - | 5.18.0.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |
@types / underscore
|
1.3.2 | 1.12.1 |