Описание
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-handlebars | fixed | 3:4.7.6+~4.1.0-2 | package | |
| node-handlebars | fixed | 3:4.1.0-1+deb10u3 | buster | package |
| libjs-handlebars | removed | package | ||
| libjs-handlebars | ignored | stretch | package |
Примечания
https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8
https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767
EPSS
Связанные уязвимости
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Remote code execution in handlebars when compiling templates
EPSS