RSS   Vulnerabilities for 'Handlebars'   RSS

2021-05-04
 
CVE-2021-23383

NVD-CWE-Other
 

 
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.

 
2021-04-12
 
CVE-2021-23369

NVD-CWE-noinfo
 

 
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

 
2020-09-30
 
CVE-2019-20922

CWE-835
 

 
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

 


Copyright 2024, cxsecurity.com

 

Back to Top