CVE-2019-19919
ADVISORY - githubSummary
Versions of handlebars
prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' __proto__
and __defineGetter__
properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Recommendation
Upgrade to version 3.0.8, 4.3.0 or later.
Common Weakness Enumeration (CWE)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities
Modification of Assumed-Immutable Data (MAID)
NIST
3.9
CVSS SCORE
9.8criticalGitHub
CVSS SCORE
9.8criticalDebian
-
Ubuntu
3.9
CVSS SCORE
9.8mediumRed Hat
1.6
CVSS SCORE
4.2lowChainguard
CGA-24r7-h5q5-23g3
-
Chainguard
CGA-7vj9-mpfx-257m
-
Chainguard
CGA-c3rm-q6m9-w8x3
-
Chainguard
CGA-44xm-j54x-qpcp
-
Chainguard
CGA-rxm8-q646-5x45
-
Chainguard
CGA-h2gf-vp52-685r
-
Chainguard
CGA-qhv8-p3fx-24cp
-
Chainguard
CGA-qqjh-jcgv-3hf6
-
Chainguard
CGA-v8qx-6rjm-9pp4
-
Chainguard
CGA-58hc-rv25-5r96
-
Chainguard
CGA-cwm3-8hq7-mhp9
-
Chainguard
CGA-fpxp-6479-8p97
-
Chainguard
CGA-mf9x-rmf7-f7gm
-
Chainguard
CGA-cgp2-hjqv-4476
-
Chainguard
CGA-gf72-ppfw-27gf
-
Chainguard
CGA-h3ff-xw97-gfp4
-
Chainguard
CGA-qjqv-36px-39r8
-