Handlebars.js Project Handlebars.js 1.0.7 - for Node.js

CPE Details

Handlebars.js Project Handlebars.js 1.0.7 - for Node.js
1.0.7
2022-06-03
16h48 +00:00
2022-06-21
23h38 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:handlebars.js_project:handlebars.js:1.0.7:-:*:*:*:node.js:*:*

Informations

Vendor

handlebars.js_project

Product

handlebars.js

Version

1.0.7

Update

-

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-19919 2019-12-20 21h50 +00:00 Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
9.8
Critique
CVE-2015-8861 2017-01-23 20h00 +00:00 The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
6.1
Moyen