CVE-2021-23358
CriticalAdvisory
Published 29 Mar 2021In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.041
- 90th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 56
- of 17,781 indexed, latest versions
- Container images
- 54
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Arbitrary Code Execution in underscore
Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 54 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| underscorenpm | 1.4.4, 1.5.2, 1.6.0, 1.7.0+6 more | 1.12.1 | 54 |
| underscoredeb | 1.7.0~dfsg-1ubuntu1, 1.8.3~dfsg-1 | 1.7.0~dfsg-1ubuntu1.1, 1.8.3~dfsg-1ubuntu0.1 | 2 |
- OSV records
- GHSA-cf4h-3jhx-xvhqUBUNTU-CVE-2021-23358
- Also known as
- USN-4913-1
Charts affected
56 by stars
Container images carrying it
54 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 86b71e90319f | underscore | 1.12.1 | 1 |
| quay.io/ | 7a4b9fedc724 | underscore | 1.12.1 | 1 |
| quay.io/ | c973e166a5dc | underscore | 1.12.1 | 1 |
| quay.io/ | cb17600883a3 | underscore | 1.12.1 | 1 |