Back

CRITICAL

nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads

Published Dec 20, 2019

Description

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Affected products

Remediation

Red Hat statement

Red Hat Quay includes Handlebars.js as a development dependency. It does not use Handlebars.js at runtime to process templates so it has been given a low impact rating.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 20, 2019
Updated Aug 5, 2024
Reserved Dec 20, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 24, 2019
ENISA EUVD
Assigner mitre
Published Dec 20, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-0803 GHSA-W457-6Q6X-CGP9