Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20922

Опубликовано: 30 сент. 2020
Источник: debian

Описание

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-handlebarsnot-affectedpackage
libjs-handlebarsnot-affectedpackage

Примечания

  • https://github.com/handlebars-lang/handlebars.js/issues/1579

  • https://github.com/handlebars-lang/handlebars.js/commit/8d5530ee2c3ea9f0aee3fde310b9f36887d00b8b

  • https://snyk.io/vuln/SNYK-JS-HANDLEBARS-480388

  • https://www.npmjs.com/advisories/1300

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

CVSS3: 7.5
redhat
больше 6 лет назад

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

CVSS3: 7.5
nvd
больше 5 лет назад

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

CVSS3: 7.5
github
почти 4 года назад

Regular Expression Denial of Service in Handlebars