Skip to content

Commit

Permalink
add CVE-2021-23369 and CVE-2021-23383 for handlebars-source (#728)
Browse files Browse the repository at this point in the history
  • Loading branch information
ddalcino committed Jan 18, 2024
1 parent b014670 commit 98efdaa
Show file tree
Hide file tree
Showing 2 changed files with 30 additions and 0 deletions.
15 changes: 15 additions & 0 deletions gems/handlebars-source/CVE-2021-23369.yml
@@ -0,0 +1,15 @@
---
gem: handlebars-source
cve: 2021-23369
ghsa: f2jv-r9rf-7988
url: https://github.com/advisories/GHSA-f2jv-r9rf-7988
title: Remote code execution in handlebars when compiling templates
date: 2021-04-12
description: |
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when
selecting certain compiling options to compile templates coming from an untrusted source.
This vulnerability has been assigned the CVE identifier CVE-2021-23369.
cvss_v3: 9.8
patched_versions:
- ">= 4.7.7"
15 changes: 15 additions & 0 deletions gems/handlebars-source/CVE-2021-23383.yml
@@ -0,0 +1,15 @@
---
gem: handlebars-source
cve: 2021-23383
ghsa: 765h-qjxv-5f44
url: https://github.com/advisories/GHSA-765h-qjxv-5f44
title: Prototype Pollution in handlebars
date: 2021-05-04
description: |
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when
selecting certain compiling options to compile templates coming from an untrusted source.
This vulnerability has been assigned the CVE identifier CVE-2021-23383.
cvss_v3: 9.8
patched_versions:
- ">= 4.7.7"

0 comments on commit 98efdaa

Please sign in to comment.