CVE-2021-23369

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-23369
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-23369.json
Aliases
  • GHSA-f2jv-r9rf-7988
  • SNYK-JAVA-ORGWEBJARS-1074950
  • SNYK-JAVA-ORGWEBJARSBOWER-1074951
  • SNYK-JAVA-ORGWEBJARSNPM-1074952
  • SNYK-JS-HANDLEBARS-1056767
Published
2021-04-12T14:15:14Z
Modified
2023-11-29T08:42:41.951172Z
Details

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

References

Affected packages

Git / github.com/handlebars-lang/handlebars.js

Affected ranges

Type
GIT
Repo
https://github.com/handlebars-lang/handlebars.js
Events
Introduced
0The exact introduced commit is unknown
Fixed
Fixed

Affected versions

0.*

0.9.0.pre.4

1.*

1.0.0
1.0.0-rc.3
1.0.0-rc.4
1.0.0.beta.1
1.0.rc.1
1.0.rc.2

v1.*

v1.0.10
v1.0.11
v1.0.12
v1.0.5beta
v1.0.6
v1.0.6-2
v1.0.6beta
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.1.2
v1.2.0
v1.2.1
v1.3.0

v2.*

v2.0.0
v2.0.0-alpha.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-beta.1

v3.*

v3.0.0
v3.0.1
v3.0.2
v3.0.3

v4.*

v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.12
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v4.1.2-0
v4.2.0
v4.2.1
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.5.3
v4.6.0
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6