Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security - dependency "underscore" prior to version 1.12.1 allows arbitrary code execution #275

Closed
janzelc-trifecta opened this issue Jun 2, 2023 · 1 comment

Comments

@janzelc-trifecta
Copy link

https://nvd.nist.gov/vuln/detail/CVE-2021-23358

@janzelc-trifecta janzelc-trifecta changed the title Security - dependency "underscore" prior to version 1.12.1 allow arbitrary code execution Security - dependency "underscore" prior to version 1.12.1 allows arbitrary code execution Jun 2, 2023
@mcab
Copy link
Member

mcab commented Jun 14, 2023

Looks like the function in question (template, from jashkenas/underscore#2915) must be specifically called.

Additionally, package.json refers to underscore via ^1.8.0. Semantic versioning will pull in the latest version underneath that major version, which is currently 1.13.6.

This issue does not seem to be valid for this package. Please comment if that is not the case.

@mcab mcab closed this as completed Jun 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants