OESA-2021-1196
Dashboard / Vulnerabilities / OESA-2021-1196
Summary: nodejs-handlebars security update
Details: Handlebars.js is an extension to the Mustache templating language created by Chris Wanstrath. Handlebars.js and Mustache are both logicless templating languages that keep the view and the code separated like we all know they should be. Security Fix(es): The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.(CVE-2021-23383)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1196, https://nvd.nist.gov/vuln/detail/CVE-2021-23383
Affected packages
Package
Name: nodejs-handlebars
Purl: pkg:rpm/openEuler/nodejs-handlebars&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
