Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cqr-58rm-57f8

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Arbitrary Code Execution in Handlebars

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

Пакеты

Наименование

handlebars

npm
Затронутые версииВерсия исправления

< 3.0.8

3.0.8

Наименование

handlebars

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.5.3

4.5.3

EPSS

Процентиль: 58%
0.00366
Низкий

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 5 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
redhat
больше 6 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
nvd
больше 5 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
debian
больше 5 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrar ...

EPSS

Процентиль: 58%
0.00366
Низкий

8.1 High

CVSS3

Дефекты

CWE-94