Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lodash | Lodash | * | 4.17.21 (excluding) |
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | RedHat | rhacm2/application-ui-rhel8:v2.3.0-120 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | RedHat | rhacm2/kui-web-terminal-rhel8:v2.3.0-51 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | RedHat | rhacm2/search-api-rhel8:v2.3.0-46 | * |
| Red Hat Migration Toolkit for Containers 1.7 | RedHat | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | * |
| Red Hat OpenShift Container Platform 4.8 | RedHat | openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream | * |
| Red Hat OpenShift Container Platform 4.8 | RedHat | openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream | * |
| Red Hat OpenShift Container Platform 4.8 | RedHat | openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream | * |
| Red Hat OpenShift Container Platform 4.8 | RedHat | openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream | * |
| Red Hat OpenShift Jaeger 1.20 | RedHat | distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18 | * |
| Red Hat OpenShift Jaeger 1.20 | RedHat | distributed-tracing/jaeger-query-rhel8:1.20.4-18 | * |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | RedHat | cockpit-ovirt-0:0.15.1-2.el8ev | * |
| Red Hat Virtualization Engine 4.4 | RedHat | ovirt-engine-ui-extensions-0:1.2.6-1.el8ev | * |
| Red Hat Virtualization Engine 4.4 | RedHat | ovirt-web-ui-0:1.6.9-1.el8ev | * |
| Node-lodash | Ubuntu | bionic | * |
| Node-lodash | Ubuntu | devel | * |
| Node-lodash | Ubuntu | esm-apps/bionic | * |
| Node-lodash | Ubuntu | esm-apps/focal | * |
| Node-lodash | Ubuntu | esm-apps/jammy | * |
| Node-lodash | Ubuntu | esm-apps/noble | * |
| Node-lodash | Ubuntu | focal | * |
| Node-lodash | Ubuntu | groovy | * |
| Node-lodash | Ubuntu | hirsute | * |
| Node-lodash | Ubuntu | impish | * |
| Node-lodash | Ubuntu | jammy | * |
| Node-lodash | Ubuntu | kinetic | * |
| Node-lodash | Ubuntu | lunar | * |
| Node-lodash | Ubuntu | mantic | * |
| Node-lodash | Ubuntu | noble | * |
| Node-lodash | Ubuntu | oracular | * |
| Node-lodash | Ubuntu | plucky | * |
| Node-lodash | Ubuntu | questing | * |
| Node-lodash | Ubuntu | trusty | * |
| Node-lodash | Ubuntu | upstream | * |
| Node-lodash | Ubuntu | xenial | * |