ZeroHour

CVE-2021-23369

PoC ×4
CVSS 3.1
9.8 critical
EPSS
7%p94
Published
()
Modified
Description

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Vendors
handlebarsjs
Products
handlebars
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.