CVE-2021-23337General(lodash / active_iq_unified_manager)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • banking_corporate_lending_process_management
  • banking_credit_facilities_process_management
  • banking_extensibility_workbench

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
active_iq_unified_managerbanking_corporate_lending_process_managementbanking_credit_facilities_process_managementbanking_extensibility_workbenchbanking_supply_chain_financebanking_trade_finance_process_managementcloud_managercommunications_cloud_native_core_binding_support_functioncommunications_cloud_native_core_policycommunications_design_studio

23 versions affected across 23 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-01: 3Mentions · 2026-04-07: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-07: 104-0104-07
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-013
General3
2026-04-071
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2021-23337 - high 🚨 Lodash Template - Server-Side Template Injection (RCE) > Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template... 👾 https://cloud.projectdiscovery.io/library/CVE-2021-23337 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces that Lodash versions prior to 4.17.21 are susceptible to a server‑side template injection that can enable remote code execution, without mentioning active exploitation or remediation efforts.

    03076295
    960 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the sam… https://www.cve.org/CVERecord?id=CVE-2026-4800

    Post summary

    The excerpt references CVE‑2026‑4800 but contains no substantive details, PoC, exploit code, or patch information.

    00001204
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the sam… https://www.cve.org/CVERecord?id=CVE-2026-4800 ----- Traducción: Impacto de CVE-2026-4800: La corrección de… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-4800 and links to a related advisory, but offers no technical, exploit, or patch details, making it a general informational note.

    0000044
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-4800 - High Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.... https://www.thehackerwire.com/vulnerability/CVE-2026-4800/ https://t.co/gzYj3hy3xq

    Post summary

    The tweet references CVE-2026-4800 with a brief technical note on missing validation, but lacks any PoC, exploit, patch, or active exploitation details.

    0000055
    163 followersView on X
CPE platform detail45 entries

45 of 45 entries

PartVendorProductVersionTarget SWTarget HW
Applodashlodash-node.js-
Appnetappactive_iq_unified_manager-linux-
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appnetappactive_iq_unified_manager-windows-
Appnetappcloud_manager---
Appnetappsystem_manager9.0--
Apporaclebanking_corporate_lending_process_management14.2.0--
Apporaclebanking_corporate_lending_process_management14.3.0--
Apporaclebanking_corporate_lending_process_management14.5.0--
Apporaclebanking_credit_facilities_process_management14.2.0--
Apporaclebanking_credit_facilities_process_management14.3.0--
Apporaclebanking_credit_facilities_process_management14.5.0--
Apporaclebanking_extensibility_workbench14.2.0--
Apporaclebanking_extensibility_workbench14.3.0--
Apporaclebanking_extensibility_workbench14.5.0--
Apporaclebanking_supply_chain_finance14.2.0--
Apporaclebanking_supply_chain_finance14.3.0--
Apporaclebanking_supply_chain_finance14.5.0--
Apporaclebanking_trade_finance_process_management14.2.0--
Apporaclebanking_trade_finance_process_management14.3.0--
Apporaclebanking_trade_finance_process_management14.5.0--
Apporaclecommunications_cloud_native_core_binding_support_function1.9.0--
Apporaclecommunications_cloud_native_core_policy1.11.0--
Apporaclecommunications_design_studio7.4.2.0.0--
Apporaclecommunications_services_gatekeeper7.0--
Apporaclecommunications_session_border_controller8.4--
Apporaclecommunications_session_border_controller9.0--
Apporacleenterprise_communications_broker3.2.0--
Apporacleenterprise_communications_broker3.3.0--
Apporaclefinancial_services_crime_and_compliance_management_studio8.0.8.2.0--
Apporaclefinancial_services_crime_and_compliance_management_studio8.0.8.3.0--
Apporaclehealth_sciences_data_management_workbench2.5.2.1--
Apporaclehealth_sciences_data_management_workbench3.0.0.0--
Apporaclejd_edwards_enterpriseone_tools---
Apporaclepeoplesoft_enterprise_peopletools8.58--
Apporaclepeoplesoft_enterprise_peopletools8.59--
Apporacleprimavera_gateway---
Apporacleprimavera_unifier---
Apporacleprimavera_unifier18.8--
Apporacleprimavera_unifier19.12--
Apporacleprimavera_unifier20.12--
Apporacleretail_customer_management_and_segmentation_foundation19.0--
Appsiemenssinec_ins---
Appsiemenssinec_ins1.0--
Appsiemenssinec_ins1.0--

Explore more