QID 151020

Date Published: 2023-02-27

QID 151020: Vulnerable JavaScript Library Detected - Underscore.js

Underscore is a JavaScript library that provides a whole mess of useful functional programming helpers without extending any built-in objects.

The web application is using a JavaScript library that is known to contain at least one vulnerability.

Attackers could potentially exploit the vulnerability in the JavaScript library. The impact of a successful exploit depends on the nature of the vulnerability and how the web application makes use of the library.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to upgrade to latest Underscore.js. Please refer to the information provided in the response section. Also check the vendor's security advisories related to the vulnerable version of the library.
    Vendor References

    CVEs related to QID 151020

    Software Advisories
    Advisory ID Software Component Link