← לוח פגיעויות

CVE-2021-23369

קריטית 9.8

תיאור (מקור, אנגלית)

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

מוצרים מושפעים

handlebarsjs: handlebars

קישורים