Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19919

Опубликовано: 20 дек. 2019
Источник: debian

Описание

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-handlebarsfixed3:4.5.3-1package
node-handlebarsfixed3:4.1.0-1+deb10u1busterpackage

Примечания

  • https://www.npmjs.com/advisories/1164

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 4.2
redhat
больше 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
nvd
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
github
около 6 лет назад

Prototype Pollution in handlebars

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонентов __proto__ и __defineGetter__ properties шаблонизатора Handlebars, позволяющая нарушителю выполнить произвольный код