Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w457-6q6x-cgp9

Опубликовано: 26 дек. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Prototype Pollution in handlebars

Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Recommendation

Upgrade to version 3.0.8, 4.3.0 or later.

Пакеты

Наименование

handlebars

npm
Затронутые версииВерсия исправления

>= 4.0.0, < 4.3.0

4.3.0

Наименование

bootstrap-wysihtml5-rails

rubygems
Затронутые версииВерсия исправления

>= 0.3.3.5, <= 0.3.3.8

Отсутствует

Наименование

handlebars

npm
Затронутые версииВерсия исправления

< 3.0.8

3.0.8

EPSS

Процентиль: 95%
0.17796
Средний

9.8 Critical

CVSS3

Дефекты

CWE-1321
CWE-74

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 4.2
redhat
больше 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
nvd
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
debian
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Poll ...

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонентов __proto__ и __defineGetter__ properties шаблонизатора Handlebars, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.17796
Средний

9.8 Critical

CVSS3

Дефекты

CWE-1321
CWE-74