QID 377842

Date Published: 2022-12-20

QID 377842: Lodash Command Injection Vulnerability

Lodash is a JavaScript library which provides utility functions for common programming tasks using the functional programming paradigm.

Affected Version
lodash prior to 4.17.21

QID Detection Logic
It checks for the vulnerable version of lodash using npm list command

An attacker can exploit the system via Command Injection via the template function.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to update to the patched version of lodash modules lodash v4.17.21
    Vendor References

    CVEs related to QID 377842

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-23337 URL Logo nvd.nist.gov/vuln/detail/CVE-2021-23337