This repository has been archived by the owner on Apr 29, 2020. It is now read-only.
WS-2019-0291 (High) detected in multiple libraries #198
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0291 - High Severity Vulnerability
Vulnerable Libraries - handlebars-4.0.10.min.js, handlebars-4.0.10.js
handlebars-4.0.10.min.js
Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
Library home page: https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/4.0.10/handlebars.min.js
Path to vulnerable library: /Notabene/lib/angular-moment-master/node_modules/bower/lib/node_modules/handlebars/dist/handlebars.min.js
Dependency Hierarchy:
handlebars-4.0.10.js
Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
Library home page: https://cdnjs.cloudflare.com/ajax/libs/handlebars.js/4.0.10/handlebars.js
Path to vulnerable library: /Notabene/lib/angular-moment-master/node_modules/bower/lib/node_modules/handlebars/dist/handlebars.js
Dependency Hierarchy:
Found in HEAD commit: 1b494b93f06c2229bf7bb904b4d6148909d53589
Vulnerability Details
handlebars before 4.3.0 is vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Publish Date: 2019-10-06
URL: WS-2019-0291
CVSS 2 Score Details (7.3)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/1164
Release Date: 2019-10-06
Fix Resolution: 4.3.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: