nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution
Published Sep 30, 2020
8.1
HIGHCVSS 3.1
EPSS 3.19%
Description
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
Affected products
No data.
- < 3.0.8
- ≥ 4.0.0 · < 4.5.3
No data.
RHPAM 7.13.1 async
handlebars
Fixed · RHSA-2023:1334
Red Hat OpenShift Container Platform 4.6
openshift4/ose-logging-kibana6:v4.6.0-202106181629.p0.git.40f3e72
Fixed · RHSA-2021:2500
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.6.5-1.el8ev
Fixed · RHSA-2020:5179
OpenShift Service Mesh 1
kiali
Not affected
OpenShift Service Mesh 1
servicemesh-grafana
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
handlebars
Not affected
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Will not fix
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Will not fix
Red Hat Virtualization 4
ovirt-engine-ui-extensions
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHPAM 7.13.1 async | handlebars | Fixed | RHSA-2023:1334 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-logging-kibana6:v4.6.0-202106181629.p0.git.40f3e72 | Fixed | RHSA-2021:2500 |
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.6.5-1.el8ev | Fixed | RHSA-2020:5179 |
| OpenShift Service Mesh 1 | kiali | Not affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | handlebars | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | n/a |
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | n/a |
handlebars
npm
Introduced 4.0.0 Fixed 4.5.3handlebars
npm
Introduced 0 Fixed 3.0.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | handlebars | 4.0.0 | 4.5.3 |
| npm | handlebars | 0 | 3.0.8 |
Remediation
Red Hat statement
Red Hat Quay includes Handlebars.js as a development dependency. It does not use Handlebars.js at runtime to process templates, so it has been given a low impact rating. Red Hat Virtualization includes Handlebars.js in two components. In ovirt-engine-ui-extentions, the version used is newer and is not affected by this flaw. In ovirt-web-ui, Handlebars.js is included as a development dependency and is not used at runtime to process templates, so it has been given a low impact rating. Red Hat OpenShift Container Platform (OCP) 4 delivers the kibana package, which includes Handlebars.js. From OCP 4.6, the kibana package is no longer shipped and will not be fixed. The openshift4/ose-logging-kibana6 container includes Handlebars.js directly as container first code. The vulnerable version of Handlebars.js is also included in openshift4/ose-grafana, but as the Grafana instance is in read-only mode, the configuration/dashboards cannot be modified.
References (11)
- https://access.redhat.com/security/cve/CVE-2019-20920 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1882260 Issue Tracking
- https://github.com/advisories/GHSA-3cqr-58rm-57f8 Advisory
- https://github.com/handlebars-lang/handlebars.js/commit/156061eb7707575293613d7fdf90e2bdaac029ee
- https://github.com/handlebars-lang/handlebars.js/commit/d54137810a49939fd2ad01a91a34e182ece4528e
- https://nvd.nist.gov/vuln/detail/CVE-2019-20920
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20920
- https://www.npmjs.com/advisories/1316 x_refsource_MISCExploitThird Party Advisory
- https://www.npmjs.com/advisories/1324 x_refsource_MISCThird Party Advisory
- https://www.npmjs.com/package/handlebars
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20920 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1882260 | Issue Tracking | |
| https://github.com/advisories/GHSA-3cqr-58rm-57f8 | Advisory | |
| https://github.com/handlebars-lang/handlebars.js/commit/156061eb7707575293613d7fdf90e2bdaac029ee | ||
| https://github.com/handlebars-lang/handlebars.js/commit/d54137810a49939fd2ad01a91a34e182ece4528e | ||
| https://nvd.nist.gov/vuln/detail/CVE-2019-20920 | ||
| https://snyk.io/vuln/SNYK-JS-HANDLEBARS-534478 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-20920 | ||
| https://www.npmjs.com/advisories/1316 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.npmjs.com/advisories/1324 | x_refsource_MISCThird Party Advisory | |
| https://www.npmjs.com/package/handlebars |
Change history (0)
No recorded changes yet.