Handlebars.Js Project Handlebars.Js vulnerabilities
2 known vulnerabilities affecting handlebars.js_project/handlebars.js.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-19919CRITICALCVSS 9.8v1.0.6v1.0.7+41 more2019-12-20
CVE-2019-19919 [CRITICAL] CWE-1321 CVE-2019-19919: Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code E
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
nvd
CVE-2015-8861MEDIUMCVSS 6.1fixed in 4.0.02017-01-23
CVE-2015-8861 [MEDIUM] CWE-79 CVE-2015-8861: The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site script
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
nvd