CRITICAL9.8
GHSA-765h-qjxv-5f44
Prototype Pollution in handlebars
Quick fix
GHSA-765h-qjxv-5f44 — handlebars: upgrade to the fixed version with the command below.
npm install handlebars@4.7.7Details
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23383[ADVISORY]
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427[WEB]
- https://github.com/handlebars-lang/handlebars.js[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/handlebars-source/CVE-2021-23383.yml[WEB]
- https://security.netapp.com/advisory/ntap-20210618-0007[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030[WEB]
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029[WEB]
- https://www.npmjs.com/package/handlebars[WEB]