References https://nvd.nist.gov/vuln/detail/cve-2021-23358 https://github.com/advisories/GHSA-cf4h-3jhx-xvhq https://security.snyk.io/vuln/SNYK-JS-UNDERSCORE-1080984 https://www.sentinelone.com/vulnerability-database/cve-2021-23358/ https://www.acunetix.com/vulnerabilities/web/underscore-js-improper-control-of-generation-of-code-code-injection-vulnerability-cve-2021-23358/ https://www.tenable.com/plugins/was/112982 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23358 https://jira.atlassian.com/browse/CONFSERVER-74276 https://www.tenablecloud.cn/plugins/was/112982 https://cve.imfht.com/detail/CVE-2021-23358
Related VulnerabilitiesPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpackage-json: NPM package.json DisclosurePoCCVE-2026-6875: ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCEUniFi OS Server latest_package 命令执行漏洞(CVE-2026-34908/CVE-2026-34909/CVE-2026-34910)PoCdevtron-env-config-js: Devtron JavaScript Environment Configuration - ExposurePoCCVE-2017-17092: WordPress < 4.9.1 - Authenticated JavaScript File UploadWebmin /package-updates/update.cgi 命令执行漏洞(CVE-2022-36446)PoCCVE-2021-28918: Netmask NPM Package - Server-Side Request ForgeryPoCCVE-2022-29078: Node.js Embedded JavaScript 3.1.6 - Template InjectionPoCCVE-2023-29827: Embedded JavaScript(EJS) 3.1.6 - Template InjectionPoCCVE-2024-8698: Keycloak - SAML Core Package Signature Validation Flaw