QID 981501
QID 981501: Nodejs (npm) Security Update for underscore (GHSA-cf4h-3jhx-xvhq)
The package `underscore` from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cf4h-3jhx-xvhq for updates pertaining to this vulnerability.
Vendor References
- GHSA-cf4h-3jhx-xvhq -
github.com/advisories/GHSA-cf4h-3jhx-xvhq
CVEs related to QID 981501
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cf4h-3jhx-xvhq | underscore |
|