CVE-2021-23358 - Need to upgrade Underscore.js to 1.13.1 or higher

XMLWordPrintable

    • 8.11
    • 7
    • Severity 2 - Major
    • 37

      Issue Summary

      Jira system is currently using underscore.js 1.9.1. However, it is being affected due to CVE-2021-23358

      • The package underscore from 1.13.0-0 and before 1.13.0-2
      • From 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

      Steps to Reproduce

      1. Install Jira Software 8.17 or below;

      Expected Results

      Have Jira using  underscore.js 1.13.1 or higher.

      Actual Results

      Jira is using underscore.js 1.9.1

      Workaround

      No workaround is available.

            Assignee:
            Mateusz Witkowski
            Reporter:
            Henrique Girardi (Inactive)
            Votes:
            5 Vote for this issue
            Watchers:
            19 Start watching this issue

              Created:
              Updated:
              Resolved: