VDB
RHSA-2021%3A1448
RHSA-2021%3A1448
PUBLISHED
CVSS 7.199999809265137 HIGH
A flaw was found in nodejs-underscore. Arbitrary code execution via the template function is possible, particularly when a variable property is passed as an argument as it is not sanitized. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/acm-operator-bundle@sha256:ea42543f1127fd6ec53cf7f6c7f61f3e0b62f1b210844584d89d60c4bf53fef9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.0 for RHEL 8 | rhacm2/acm-operator-bundle@sha256:ea42543f1127fd6ec53cf7f6c7f61f3e0b62f1b210844584d89d60c4bf53fef9_amd64 |
Timeline
- Apr 28, 2021 CVE Published
- Feb 26, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:1448 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1940452 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1944286 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1448.json advisory
- https://access.redhat.com/security/cve/CVE-2021-23358 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-23358 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-23358 advisory