CVE-2019-19919: Critical severity Handlebars.js Project Handlebars.js Node.js vulnerability
A flaw was found in nodejs-handlebars, where it is vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which allows an attacker to execute arbitrary code through crafted payloads. The highest threat from this vulnerability is to confidentiality and integrity.
Other sources
Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Recommendation
Upgrade to version 3.0.8, 4.3.0 or later.
— GitHub
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-19919?
CVE-2019-19919 is a vulnerability in handlebars prior to version 4.3.0 that allows for Prototype Pollution leading to Remote Code Execution.
How severe is CVE-2019-19919?
CVE-2019-19919 is rated as critical with a severity score of 9.8 out of 10.
Which software versions are affected by CVE-2019-19919?
Versions 1.0.6 to 1.3.0 and 2.0.0 to 4.2.2 of Handlebars.js Project Handlebars.js, as well as versions of nodejs-handlebars prior to 4.3.0 are affected.
How can I fix CVE-2019-19919?
To fix CVE-2019-19919, update to version 4.3.0 of nodejs-handlebars or ensure you are using a non-vulnerable version of Handlebars.js Project Handlebars.js.
Where can I find more information about CVE-2019-19919?
You can find more information about CVE-2019-19919 in the following references: [Link 1](https://www.npmjs.com/advisories/1164), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1789961), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1789962).