All versions of package lodash; all versions of package org.fujion.webjars:lodash are vulnerable to Command Injection via template. Reference: https://snyk.io/vuln/SNYK-JS-LODASH-1040724
Created lodash tracking bugs for this issue: Affects: fedora-32 [bug 1928939] Created nodejs-lodash tracking bugs for this issue: Affects: epel-all [bug 1928938]
While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable template function.
Upstream fix: https://github.com/lodash/lodash/pull/5085/commits/23125079fc43ece274c0e3a49a644ae2dae8b1d3 [not merged yet]
Upstream Commit: https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c
Statement: In OpenShift ServiceMesh (OSSM) and Red Hat OpenShift Jaeger (RHOSJ) the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is Low. While Red Hat Virtualization's cockpit-ovirt has a dependency on lodash it doesn't use the vulnerable template function. While Red Hat Quay has a dependency on lodash via restangular it doesn't use the vulnerable template function.
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8 Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 7 Via RHSA-2021:1168 https://access.redhat.com/errata/RHSA-2021:1168
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-23337
This issue has been addressed in the following products: Red Hat Virtualization Engine 4.4 Via RHSA-2021:2179 https://access.redhat.com/errata/RHSA-2021:2179
This issue has been addressed in the following products: Red Hat OpenShift Jaeger 1.20 Via RHSA-2021:2543 https://access.redhat.com/errata/RHSA-2021:2543
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2021:2438 https://access.redhat.com/errata/RHSA-2021:2438
updated the public date - originally it was incorrectly set to 2019. Thanks @btarasso
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2021:3016 https://access.redhat.com/errata/RHSA-2021:3016
This issue has been addressed in the following products: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Via RHSA-2021:3459 https://access.redhat.com/errata/RHSA-2021:3459
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.7 Via RHSA-2022:6429 https://access.redhat.com/errata/RHSA-2022:6429