CRITICAL9.8
GHSA-f2jv-r9rf-7988
Remote code execution in handlebars when compiling templates
Quick fix
GHSA-f2jv-r9rf-7988 — handlebars: upgrade to the fixed version with the command below.
npm install handlebars@4.7.7Details
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars:handlebars
Introduced in:
0Fixed in: 4.7.7Fix
# pom.xml: bump <version>4.7.7</version> for org.webjars:handlebarsMaven/org.webjars.npm:handlebars
Introduced in:
0Fixed in: 4.7.7Fix
# pom.xml: bump <version>4.7.7</version> for org.webjars.npm:handlebarsMaven/org.webjars.bowergithub.wycats:handlebars.js
Introduced in:
0Fixed in: 4.7.7Fix
# pom.xml: bump <version>4.7.7</version> for org.webjars.bowergithub.wycats:handlebars.jsReferences
- https://nvd.nist.gov/vuln/detail/CVE-2021-23369[ADVISORY]
- https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8[WEB]
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427[WEB]
- https://github.com/wycats/handlebars.js[PACKAGE]
- https://security.netapp.com/advisory/ntap-20210604-0008[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952[WEB]
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767[WEB]