Issues

Select view

Select search mode

 
50 of 282

Prototype Pollution in handlebars

Description

Versions of `handlebars` prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects' prototype, thus allowing an attacker to execute arbitrary code on the server.

  1.  

    1. Recommendation

For handlebars 4.1.x upgrade to 4.1.2 or later.

For handlebars 4.0.x upgrade to 4.0.14 or later.

Repository: OpenNMS/opennms-compass (https://github.com/OpenNMS/opennms-compass)
Dependabot: https://github.com/OpenNMS/opennms-compass/security/dependabot/5
CVE:
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
GHSA: GHSA-q42p-pg8m-cqh6
Severity: high
Ecosystem: npm
Package Name: handlebars
Vulnerable Version Range: >= 4.0.0, < 4.0.14
First Patched Version: 4.0.14

Details

Assignee

Reporter

Priority

PagerDuty

Created August 2, 2023 at 12:48 PM
Updated August 2, 2023 at 3:27 PM

Activity

Show:

chiuen (Qun)August 2, 2023 at 3:26 PM

Infosec evaluated at the following risk:

CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:U/CR:H/IR:H/AR:H/MAV:X/MAC:X/MPR:X/MUI:X/MS:X/MC:X/MI:X/MA:X

CVSS Score: 7.0 x likelihood medium 0.8 = 5.6 medium