4.7.7
11 years ago
2 years ago
Known vulnerabilities in the org.webjars:handlebars package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. POC
How to fix Prototype Pollution? Upgrade | [,4.7.7) |
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source. POC
How to fix Remote Code Execution (RCE)? Upgrade | [,4.7.7) |
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution. Prototype access to the template engine allows for potential code execution. How to fix Prototype Pollution? Upgrade | [,4.5.3) |
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution. It is possible to add or modify properties to the Object prototype through a malicious template. This may allow attackers to crash the application or execute Arbitrary Code in specific conditions. How to fix Prototype Pollution? Upgrade | [,4.5.3) |
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Arbitrary Code Execution. The package's lookup helper doesn't validate templates correctly, allowing attackers to submit templates that execute arbitrary JavaScript in the system. How to fix Arbitrary Code Execution? Upgrade | [,4.5.3) |
org.webjars:handlebars is a extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution.
Templates may alter an Object's How to fix Prototype Pollution? Upgrade | [,4.7.7) |
org.webjars:handlebars is an extension to the Mustache templating language. Affected versions of this package are vulnerable to Prototype Pollution. Templates may alter an Objects' prototype, thus allowing an attacker to execute arbitrary code on the server. How to fix Prototype Pollution? Upgrade | [,4.0.13)[4.1.0,4.1.2) |
handlebars provides the power necessary to let you build semantic templates. When using attributes without quotes in a handlebars template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an attacker can influence the value entered into the template. If the handlebars template is used to render user-generated content, this vulnerability may escalate to a persistent XSS vulnerability. | [,4.0.0) |