Skip to content
This repository has been archived by the owner on Jan 8, 2021. It is now read-only.

WS-2019-0491 (High) detected in handlebars-4.0.11.tgz #189

Open
mend-bolt-for-github bot opened this issue Nov 10, 2020 · 0 comments
Open

WS-2019-0491 (High) detected in handlebars-4.0.11.tgz #189

mend-bolt-for-github bot opened this issue Nov 10, 2020 · 0 comments
Labels
security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

WS-2019-0491 - High Severity Vulnerability

Vulnerable Library - handlebars-4.0.11.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.0.11.tgz

Path to dependency file: recursos.osweekends.com/client/package.json

Path to vulnerable library: recursos.osweekends.com/client/node_modules/handlebars/package.json

Dependency Hierarchy:

  • karma-coverage-1.1.1.tgz (Root Library)
    • istanbul-0.4.5.tgz
      • handlebars-4.0.11.tgz (Vulnerable Library)

Found in HEAD commit: 6352e0210f400c446da6f7bbb941ec356ceec84f

Vulnerability Details

handlebars before 4.4.5 is vulnerable to Denial of Service. The package's parser may be forced into an endless loop while processing specially-crafted templates. This may allow attackers to exhaust system resources leading to Denial of Service.

Publish Date: 2019-11-04

URL: WS-2019-0491

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.npmjs.com/advisories/1300

Release Date: 2019-11-04

Fix Resolution: handlebars - 4.4.5


Step up your Open Source Security Game with WhiteSource here

@mend-bolt-for-github mend-bolt-for-github bot added the security vulnerability Security vulnerability detected by WhiteSource label Nov 10, 2020
# for free to subscribe to this conversation on GitHub. Already have an account? #.
Labels
security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants