CVE-2021-23337

Aliases:GHSA-35jh-r3h4-6jhmCVE-2026-4800GHSA-r5fr-rjxr-66jc
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 31 Mar 2026, 19:25
Last modified:21 Jul 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
47/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
22.41% HIGH
22% probability +21.67%
KEV
Not listed
Ransomware
No reports
Public exploits
6 found
Dark Web
Not detected

Timeline

31 Mar 2026, 19:25
Published
Vulnerability first disclosed
21 Jul 2026, 12:04
Last Modified
Vulnerability information updated

Description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.5AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 22.41% Percentile: 97%

Techniques & Countermeasures

  • CWE-94Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Systems

  • RubyGemslodash-rails

    < 4.17.21

  • lodashlodash

    < 4.17.21 | ≥ 4.0.0, < 4.18.0

  • lodashlodash-amd

    ≥ 4.0.0, < 4.18.0

  • lodashlodash-es

    ≥ 4.0.0, < 4.18.0

  • lodashlodash.template

    ≥ 4.0.0, < 4.18.0

  • netappactive_iq_unified_manager

    na

  • netappcloud_manager

    na

  • netappsystem_manager

    9.0

  • Npmlodash

    < 4.17.21 | ≥ 4.0.0, < 4.18.0

  • Npmlodash-amd

    ≥ 4.0.0, < 4.18.0

  • Npmlodash-es

    < 4.17.21 | ≥ 4.0.0, < 4.18.0

  • Npmlodash-template

    ≤ 1.0.0

  • Npmlodash.template

    ≤ 4.5.0 | ≥ 4.0.0, < 4.18.0

  • oraclebanking_corporate_lending_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_credit_facilities_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_extensibility_workbench

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_supply_chain_finance

    14.2.0 | 14.3.0 | 14.5.0

  • oraclebanking_trade_finance_process_management

    14.2.0 | 14.3.0 | 14.5.0

  • oraclecommunications_cloud_native_core_binding_support_function

    1.9.0

  • oraclecommunications_cloud_native_core_policy

    1.11.0

  • oraclecommunications_design_studio

    7.4.2.0.0

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_border_controller

    8.4 | 9.0

  • oracleenterprise_communications_broker

    3.2.0 | 3.3.0

  • oraclefinancial_services_crime_and_compliance_management_studio

    8.0.8.2.0 | 8.0.8.3.0

  • oraclehealth_sciences_data_management_workbench

    2.5.2.1 | 3.0.0.0

  • oraclejd_edwards_enterpriseone_tools

    < 9.2.6.1

  • UnknownPeopleSoft Enterprise PeopleTools

    8.58 | 8.59

  • oracleprimavera_gateway

    ≥ 17.12.0, ≤ 17.12.11 | ≥ 18.8.0, ≤ 18.8.12 | ≥ 19.12.0, ≤ 19.12.11 | ≥ 20.12.0, ≤ 20.12.7

  • oracleprimavera_unifier

    ≥ 17.7, ≤ 17.12 | 18.8 | 19.12 | 20.12

  • oracleretail_customer_management_and_segmentation_foundation

    19.0

  • siemenssinec_ins

    < 1.0 | 1.0 | 1.0:sp1

References (92)