Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23369

Опубликовано: 12 апр. 2021
Источник: debian

Описание

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-handlebarsfixed3:4.7.6+~4.1.0-2package
node-handlebarsfixed3:4.1.0-1+deb10u3busterpackage
libjs-handlebarsremovedpackage
libjs-handlebarsignoredstretchpackage

Примечания

  • https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8

  • https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427

  • https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 9.8
redhat
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 5.6
nvd
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 9.8
github
больше 5 лет назад

Remote code execution in handlebars when compiling templates