Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19919

Опубликовано: 24 сент. 2019
Источник: redhat
CVSS3: 4.2
EPSS Средний

Описание

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.

A flaw was found in nodejs-handlebars, where it is vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which allows an attacker to execute arbitrary code through crafted payloads. The highest threat from this vulnerability is to confidentiality and integrity.

Отчет

Red Hat Quay includes Handlebars.js as a development dependency. It does not use Handlebars.js at runtime to process templates so it has been given a low impact rating.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11kibanaAffected
Red Hat OpenShift Container Platform 4kibanaAffected
Red Hat Quay 3nodejs-handlebarsAffected
RHPAM 7.13.1 asynchandlebarsFixedRHSA-2023:133420.03.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-471
https://bugzilla.redhat.com/show_bug.cgi?id=1789959nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads

EPSS

Процентиль: 95%
0.17796
Средний

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
nvd
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

CVSS3: 9.8
debian
около 6 лет назад

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Poll ...

CVSS3: 9.8
github
около 6 лет назад

Prototype Pollution in handlebars

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость компонентов __proto__ и __defineGetter__ properties шаблонизатора Handlebars, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.17796
Средний

4.2 Medium

CVSS3