Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23369

Опубликовано: 12 апр. 2021
Источник: nvd
CVSS3: 5.6
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*
Версия до 4.7.7 (исключая)

EPSS

Процентиль: 94%
0.07028
Низкий

5.6 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 9.8
redhat
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 5.6
debian
больше 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Exec ...

CVSS3: 9.8
github
больше 5 лет назад

Remote code execution in handlebars when compiling templates

EPSS

Процентиль: 94%
0.07028
Низкий

5.6 Medium

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

NVD-CWE-noinfo