Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-20920

Опубликовано: 30 сент. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*
Версия до 3.0.8 (исключая)
cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*
Версия от 4.0.0 (включая) до 4.5.3 (исключая)

EPSS

Процентиль: 58%
0.00366
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 5 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
redhat
больше 6 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

CVSS3: 8.1
debian
больше 5 лет назад

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrar ...

CVSS3: 8.1
github
почти 4 года назад

Arbitrary Code Execution in Handlebars

EPSS

Процентиль: 58%
0.00366
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-94