ZeroHour

CVE-2019-20922

CVSS 3.1
7.5 high
EPSS
4%p89
Published
()
Modified
Description

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

Vendors
handlebarsjs
Products
handlebars
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.