IBM Support

LI82093: CVE-2021-23358 UNDERSCORE PACKAGE

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • CVE-2021-23358 underscore package
    

Local fix

Problem summary

  • <span style="font-size:12px"><span
    style="background-color:rgb(255, 255, 255);color:rgb(36, 41,
    46);font-family:-apple-system,system-ui,segoe
    ui,helvetica,arial,sans-serif,apple color emoji,segoe ui
    emoji">The package underscore from 1.13.0-0 and before 1.13.0-2,
    from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code
    Execution via the template function, particularly when a
    variable property is passed as an argument as it is not
    sanitized.</span></span>
    

Problem conclusion

  • API Connect v5.0.8.11-iFix will contain underscore@1.12.1 and
    above, which will resolve this security concern.
    

Temporary fix

Comments

APAR Information

  • APAR number

    LI82093

  • Reported component name

    API CONNECT ENT

  • Reported component ID

    5725Z2201

  • Reported release

    508

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2021-04-09

  • Closed date

    2021-04-13

  • Last modified date

    2021-04-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    API CONNECT ENT

  • Fixed component ID

    5725Z2201

Applicable component levels

  • R508 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSMNED","label":"IBM API Connect"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"508","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 September 2021