CVE-2019-20920
🟠 Łataj w tym tygodniu
Wykonanie dowolnego kodu w Handlebars umożliwia atakującym uruchomienie JavaScript na serwerze lub w przeglądarce.
CVSS
8.1
EPSS
3.2%
Exploit
poc
Vendor
handlebarsjs
Opis źródłowy (NVD)
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
exploit rce xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.2% |
| Opublikowano (NVD) | 2020-09-30 18:15:17 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:54 UTC |
Referencje
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478 ([email protected]) [Third Party Advisory]
- https://www.npmjs.com/advisories/1316 ([email protected]) [Exploit, Third Party Advisory]
- https://www.npmjs.com/advisories/1324 ([email protected]) [Third Party Advisory]