Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-23369

Опубликовано: 12 апр. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 5.6

Описание

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

jammy

DNE

kinetic

DNE

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

3:4.7.7+~4.1.0-1
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

3:4.7.7+~4.1.0-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needed
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

7.5 High

CVSS2

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 5.6
nvd
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

CVSS3: 5.6
debian
почти 5 лет назад

The package handlebars before 4.7.7 are vulnerable to Remote Code Exec ...

CVSS3: 9.8
github
почти 5 лет назад

Remote code execution in handlebars when compiling templates

7.5 High

CVSS2

5.6 Medium

CVSS3