Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cqr-58rm-57f8

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Arbitrary Code Execution in Handlebars

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

Пакеты

Наименование

handlebars

npm
Затронутые версииВерсия исправления

< 3.0.8

3.0.8

Наименование

handlebars

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.5.3

4.5.3

EPSS

Процентиль: 87%
0.03193
Низкий

8.1 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
redhat
почти 7 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
nvd
почти 6 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
debian
почти 6 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrar ...

EPSS

Процентиль: 87%
0.03193
Низкий

8.1 High

CVSS3

Дефекты

CWE-94