Version 1.13.7

underscore

JavaScript's utility _ belt

Install Instructions

npm install underscore
Current Version Release Date July 24, 2024
Package URL (purl) pkg:npm/underscore@1.13.7

Find underscore vulnerabilities in your supply chain.

Scan for Free

underscore Vulnerabilities

Sort by
icon CVE (Latest)
  • icon CVE (Latest)
  • icon CVE (Oldest)
  • icon CVSS Score (Highest)
  • icon CVSS Score (Lowest)
CVE question mark icon CVSS Score question mark icon CWE(s) question mark icon EPSS Score question mark icon EPSS % question mark icon Impacted Versions
CVE-2021-23358 Low 3.3 CWE-94 0.00685 0.7989
  • 1.3.2–1.12.0

underscore Vulnerability Remediation Guidance

CVE Description Full list of Impacted Versions Fix
CVE-2021-23358 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized. 1.4.4, 1.9.2, 1.8.0, 1.6.0, 1.8.3, 1.10.0, 1.5.2, 1.5.1 (Show all) Minor → 1.12.1

Instantly see if these underscore vulnerabilities affect your code.

Scan for Free