CVE-2021-23358

Arbitrary Code Injection

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.


We have discovered 239,584 live websites that are affected by CVE-2021-23358.

Test my site




Affected Software

Product  underscore
Category JavaScript Libraries
Vulnerable Domains239,584 live websites (12.68% of underscore install base)
Vulnerable Versions
  • from 0 before 1.12.1
Vulnerable Versions Count41 versions ( 82.00% of all versions)



Details

  • Published - Mar 29, 2021
  • Updated - Sep 17, 2024

Credits

  • Alessio Della Libera (@d3lla)

CVE-2021-23358 usage by Country

United States82,063 websites



Germany24,141 websites
France15,212 websites
Canada11,394 websites
GB7,962 websites
Russia7,429 websites
Netherlands7,087 websites
Italy6,574 websites
Poland5,916 websites
Spain5,747 websites

CVE-2021-23358 usage by TLD

.com105,698 websites
.org11,012 websites
.de10,498 websites
.net6,286 websites
.nl6,202 websites
.ru6,183 websites
.co.uk6,131 websites
.it5,452 websites
.fr5,378 websites
.pl4,772 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-23358

Top websites that are affected by CVE-2021-23358. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States***
************.com United States*,***
**********.com United States*,***
*******.com United States*,***
********.com United States*,***
***.com United States*,***
******.com United States*,***
*************.com United States*,***
**********.org United States*,***
************.com United States*,***
See full domain list

FAQ

A total of 239,584 websites have been identified as vulnerable to CVE-2021-23358, discovered through global website indexing conducted by WebTechSurvey.
underscore is susceptible to CVE-2021-23358 vulnerability.
underscore versions before 1.12.1 are vulnerable to CVE-2021-23358.
Version 1.12.1 of underscore addresses the CVE-2021-23358 security vulnerability.

References