CVE-2021-23369
קריטית 9.8
תיאור (מקור, אנגלית)
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
מוצרים מושפעים
handlebarsjs: handlebars
קישורים
- https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321… PatchThird Party Advisory
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be… PatchThird Party Advisory
- https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321… PatchThird Party Advisory
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be… PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951 ExploitThird Party Advisory