First published: Mon Apr 12 2021(Updated: )
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Handlebarsjs Handlebars | <4.7.7 | |
Netapp E-series Performance Analyzer | ||
npm/handlebars | <4.7.7 | 4.7.7 |
redhat/handlebars | <4.7.7 | 4.7.7 |
<4.7.7 | ||
https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this issue is CVE-2021-23383.
The severity level of CVE-2021-23383 is critical.
The affected software for CVE-2021-23383 includes the package handlebars before version 4.7.7 and Handlebarsjs Handlebars up to version 4.7.7.
An attacker can exploit this vulnerability by providing untrusted handlebars templates, allowing them to execute arbitrary code in the javascript system.
Yes, the fix for CVE-2021-23383 is to upgrade to version 4.7.7 of the handlebars package.