The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "1.4.4-2ubuntu1+esm1", "binary_name": "libjs-underscore" }, { "binary_version": "1.4.4-2ubuntu1+esm1", "binary_name": "node-underscore" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.7.0~dfsg-1ubuntu1.1", "binary_name": "libjs-underscore" }, { "binary_version": "1.7.0~dfsg-1ubuntu1.1", "binary_name": "node-underscore" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.8.3~dfsg-1ubuntu0.1", "binary_name": "libjs-underscore" }, { "binary_version": "1.8.3~dfsg-1ubuntu0.1", "binary_name": "node-underscore" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.9.1~dfsg-1ubuntu0.20.04.1", "binary_name": "libjs-underscore" }, { "binary_version": "1.9.1~dfsg-1ubuntu0.20.04.1", "binary_name": "node-underscore" } ] }