Done
Details
Details
Assignee
Igor Godlevskyi
Igor Godlevskyi(Deactivated)Reporter
Peter Murray
Peter MurrayPriority
Story Points
1
Sprint
None
Development Team
Spitfire
Fix versions
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created January 2, 2020 at 7:41 PM
Updated January 31, 2020 at 1:31 PM
Resolved January 31, 2020 at 1:31 PM
As reported by GitHub:
Details
CVE-2019-19919
high severity
*Vulnerable versions:* < 4.3.0
*Patched version:* 4.3.0
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's *proto* and *defineGetter* properties, which may allow an attacker to execute arbitrary code through crafted payloads.