Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23369

Опубликовано: 12 апр. 2021
Источник: debian
EPSS Низкий

Описание

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-handlebarsfixed3:4.7.6+~4.1.0-2package
node-handlebarsfixed3:4.1.0-1+deb10u3busterpackage
libjs-handlebarsremovedpackage
libjs-handlebarsignoredstretchpackage

Примечания

  • https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8

  • https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427

  • https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767

EPSS

Процентиль: 82%
0.01808
Низкий

Связанные уязвимости

CVSS3: 5.6
ubuntu
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 9.8
redhat
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 5.6
nvd
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 9.8
github
почти 5 лет назад

Remote code execution in handlebars when compiling templates

EPSS

Процентиль: 82%
0.01808
Низкий