Description
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w457-6q6x-cgp9 | Prototype Pollution in handlebars |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:32:09.526Z
Reserved: 2019-12-20T00:00:00.000Z
Link: CVE-2019-19919
No data.
Status : Modified
Published: 2019-12-20T23:15:11.480
Modified: 2024-11-21T04:35:39.797
Link: CVE-2019-19919
OpenCVE Enrichment
No data.
Github GHSA