← לוח פגיעויות

CVE-2021-23383

קריטית 9.8

תיאור (מקור, אנגלית)

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-1321

מוצרים מושפעים

handlebarsjs: handlebars; netapp: e-series performance analyzer

קישורים