Command Injection
Published Feb 15, 2021
7.2
HIGHCVSS 3.1
EPSS 21.33%
Description
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Affected products
- Vendor n/a Product Lodash Defaultn/a
- Version prior to 4.17.21StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Lodash | n/a |
|
Configuration 2
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 14.2.0
- 14.3.0
- 14.5.0
- 1.9.0
- 1.11.0
- 7.4.2.0.0
- 7.0
- 8.4
- 9.0
- 3.2.0
- 3.3.0
- 8.0.8.2.0
- 8.0.8.3.0
- 2.5.2.1
- 3.0.0.0
- < 9.2.6.1
- 8.58
- 8.59
- ≥ 17.12.0 · ≤ 17.12.11
- ≥ 18.8.0 · ≤ 18.8.12
- ≥ 19.12.0 · ≤ 19.12.11
- ≥ 20.12.0 · ≤ 20.12.7
- ≥ 17.7 · ≤ 17.12
- 18.8
- 19.12
- 20.12
- 19.0
Configuration 3
- n/a
- n/a
- n/a
- n/a
- 9.0
No data.
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1775675922
Fixed · RHSA-2026:7329
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.4-12
Fixed · RHSA-2022:6429
Red Hat OpenShift Container Platform 4.8
openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Platform 4.8
openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Jaeger 1.20
distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18
Fixed · RHSA-2021:2543
Red Hat OpenShift Jaeger 1.20
distributed-tracing/jaeger-query-rhel8:1.20.4-18
Fixed · RHSA-2021:2543
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
cockpit-ovirt-0:0.15.1-2.el8ev
Fixed · RHSA-2021:3459
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.6-1.el8ev
Fixed · RHSA-2021:2179
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.6.9-1.el8ev
Fixed · RHSA-2021:2179
OpenShift Service Mesh 2.0
kiali
Affected
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/application-ui-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-api-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-header-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-ui-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grc-ui-api-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grc-ui-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/kui-web-terminal-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/mcm-topology-api-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/mcm-topology-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-api-rhel8
Affected
Red Hat Ansible Automation Platform 1.2
lodash
Affected
Red Hat Decision Manager 7
lodash
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hadoop
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-presto
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel9
Affected
Red Hat Process Automation 7
lodash
Not affected
Red Hat Quay 3
quay/quay-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1775675922 | Fixed | RHSA-2026:7329 |
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | Fixed | RHSA-2022:6429 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-console:v4.8.0-202107010336.p0.git.188a490.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-grafana:v4.8.0-202106291913.p0.git.b987e4b.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-prometheus:v4.8.0-202106291913.p0.git.f3beb88.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Jaeger 1.20 | distributed-tracing/jaeger-all-in-one-rhel8:1.20.4-18 | Fixed | RHSA-2021:2543 |
| Red Hat OpenShift Jaeger 1.20 | distributed-tracing/jaeger-query-rhel8:1.20.4-18 | Fixed | RHSA-2021:2543 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | cockpit-ovirt-0:0.15.1-2.el8ev | Fixed | RHSA-2021:3459 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.6-1.el8ev | Fixed | RHSA-2021:2179 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.6.9-1.el8ev | Fixed | RHSA-2021:2179 |
| OpenShift Service Mesh 2.0 | kiali | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-header-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/kui-web-terminal-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | lodash | Affected | n/a |
| Red Hat Decision Manager 7 | lodash | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-presto | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel9 | Affected | n/a |
| Red Hat Process Automation 7 | lodash | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Fix deferred | n/a |
lodash-template
npm
Introduced 0 Fixed not fixedlodash-rails
RubyGems
Introduced 0 Fixed 4.17.21lodash-amd
npm
Introduced 4.0.0 Fixed 4.18.0lodash
npm
Introduced 4.0.0 Fixed 4.18.0lodash-es
npm
Introduced 4.0.0 Fixed 4.18.0lodash.template
npm
Introduced 4.0.0 Fixed 4.18.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | lodash-template | 0 | not fixed |
| RubyGems | lodash-rails | 0 | 4.17.21 |
| npm | lodash-amd | 4.0.0 | 4.18.0 |
| npm | lodash | 4.0.0 | 4.18.0 |
| npm | lodash-es | 4.0.0 | 4.18.0 |
| npm | lodash.template | 4.0.0 | 4.18.0 |
Remediation
Red Hat statement
In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Jaeger (RHOSJ) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. While Red Hat Virtualization's cockpit-ovirt has a dependency on lodash it doesn't use the vulnerable template function. While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable template function.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:U/RC:C
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 21.33% (0.21333) | 97.53th | v5 (v2026.06.15) |
| Jul 24, 2026 | 21.33% (0.21333) | 97.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 22.41% (0.22410) | 97.39th | v5 (v2026.06.15) |
| Jun 11, 2026 | 2.40% (0.02399) | 85.39th | v4 (v2025.03.14) |
| May 22, 2026 | 4.31% (0.04314) | 89.01th | v4 (v2025.03.14) |
| May 7, 2026 | 3.29% (0.03287) | 87.27th | v4 (v2025.03.14) |
| Apr 8, 2026 | 4.31% (0.04314) | 88.89th | v4 (v2025.03.14) |
| Nov 21, 2025 | 0.74% (0.00741) | 72.17th | v4 (v2025.03.14) |
| Nov 18, 2025 | 10.39% (0.10395) | 92.45th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.86% (0.00859) | 73.41th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.86% (0.00858) | 82.98th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.61% (0.00606) | 77.90th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.61% (0.00606) | 75.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.11% (0.04106) | 86.02th | v2 (v2022.01.01) |
| Sep 14, 2022 | 4.11% (0.04106) | 85.41th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.96% (0.02961) | 81.88th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.20% (0.16200) | 92.74th | v2 (v2022.01.01) |
| Feb 3, 2022 | 9.45% (0.09448) | 86.95th | v1 |
| Jan 6, 2022 | 9.45% (0.09448) | 86.79th | v1 |
| Oct 21, 2021 | 2.27% (0.02273) | 78.18th | v1 |
| Oct 11, 2021 | 2.07% (0.02069) | 77.54th | v1 |
| Oct 5, 2021 | 8.66% (0.08659) | 92.87th | v1 |
| Sep 1, 2021 | 2.07% (0.02069) | 77.27th | v1 |
| Jul 21, 2021 | 2.07% (0.02069) | 0.00th | v1 |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (21)
- https://access.redhat.com/security/cve/CVE-2021-23337 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1928937 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/advisories/GHSA-35jh-r3h4-6jhm Advisory
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js#L14851
- https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851 x_refsource_MISCBroken Link
- https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2021-23337.yml
- https://nvd.nist.gov/vuln/detail/CVE-2021-23337
- https://security.netapp.com/advisory/ntap-20210312-0006 x_refsource_CONFIRMThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-23337
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.