Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23358

26
FAUCET Score

CVE-2021-23358 describes an Arbitrary Code Injection vulnerability in the Underscore.js package, specifically affecting versions 1.13.0-0 to 1.13.0-2 and 1.3.2 to 1.12.1. This flaw occurs within the template function when an unsanitized variable property is passed as an argument. With a CVSS score of 7.2 (HIGH), this vulnerability allows for high impact to confidentiality, integrity, and availability, requiring high privileges for exploitation over a network. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.3.2, < 1.12.1CPE matchmatch criteria
cpe:2.3:a:underscorejs:underscore:*:*:*:*:*:node.js:*:*
>= 1.13.0-0, < 1.13.0-2CPE matchmatch criteria
cpe:2.3:a:underscorejs:underscore:*:*:*:*:*:node.js:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
<= 5.18.0CPE matchmatch criteria
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.3LOW

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
0.7
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.09%
Probability of exploitation in next 30 days
EPSS Percentile
89.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0409 is in the 88th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

npmpatch availablevia ghsa
Product: underscoreFixed in: 1.12.1
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2.0 for RHEL 8Fixed in: rhacm2/acm-operator-bundle:v2.0.10-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7.1Fixed in: ceph-2:18.2.1-381.el9cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-engine-ui-extensions-0:1.2.7-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.4Fixed in: ovirt-web-ui-0:1.9.1-1.el8ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/grafana-rhel9:sha256:1dc2620596822eb28fb997bc51ad2ecb352011e63f4c54fb650bc3e4c8009c4e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 9Fixed in: rhceph/grafana-rhel10:sha256:2c8bad4973281d8ccdc6e4473c1ff76730323d59c3a18a948afcb1b5da520fd5
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Storage 3Fixed in: grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-grafana
redhatvendor investigatingvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ocs4/mcg-core-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 6Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-core:10.6/pki-core
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: pki-core

Vendor Advisories (3)

npmGHSA-cf4h-3jhx-xvhqcritical

Arbitrary Code Execution in underscore

May 6, 2021
redhatCVE-2021-23358Important

nodejs-underscore: Arbitrary code execution via the template function

Mar 29, 2021
microsoft2021-Mar/CVE-2021-23358Important

Arbitrary Code Injection

Mar 9, 2021

References

seclists.org / fulldisclosure/2025/Apr/14
security.netapp.com / advisory/ntap-20240808-0003
security.netapp.com / advisory/ntap-20241108-0002
github.com / jashkenas/underscore/blob/master/modules/template.js%23L71
Broken Link
lists.apache.org / thread.html/r5df90c46f7000c4aab246e947f62361ecfb849c5a553dcdb0ef545e1%40%3Cissues.cordova.apache.org%3E
lists.apache.org / thread.html/r770f910653772317b117ab4472b0a32c266ee4abbafda28b8a6f9306%40%3Cissues.cordova.apache.org%3E
lists.apache.org / thread.html/raae088abdfa4fbd84e1d19d7a7ffe52bf8e426b83e6599ea9a734dba%40%3Cissues.cordova.apache.org%3E
lists.apache.org / thread.html/rbc84926bacd377503a3f5c37b923c1931f9d343754488d94e6f08039%40%3Cissues.cordova.apache.org%3E
lists.apache.org / thread.html/re69ee408b3983b43e9c4a82a9a17cbbf8681bb91a4b61b46f365aeaf%40%3Cissues.cordova.apache.org%3E
lists.debian.org / debian-lts-announce/2021/03/msg00038.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EOKATXXETD2PF3OR36Q5PD2VSVAR6J5Z
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FGEE7U4Z655A2MK5EW4UQQZ7B64XJWBV
snyk.io / vuln/SNYK-JAVA-ORGWEBJARSBOWER-1081504
ExploitThird Party Advisory
snyk.io / vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBJASHKENAS-1081505
ExploitThird Party Advisory
snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-1081503
ExploitThird Party Advisory
snyk.io / vuln/SNYK-JS-UNDERSCORE-1080984
ExploitThird Party Advisory
debian.org / security/2021/dsa-4883
Third Party Advisory
tenable.com / security/tns-2021-14
Third Party Advisory