Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
References
Link Resource
https://www.npmjs.com/advisories/1164 Third Party Advisory
https://www.tenable.com/security/tns-2021-14 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-12-20T22:50:39

Updated: 2021-07-22T17:07:21

Reserved: 2019-12-20T00:00:00


Link: CVE-2019-19919

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-12-20T23:15:11.480

Modified: 2022-06-03T18:48:57.977


Link: CVE-2019-19919

JSON object: View

cve-icon Redhat Information

No data.

CWE