CVE-2019-19919

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
handlebars.js_projecthandlebars.js
1.0.6
handlebars.js_projecthandlebars.js
1.0.7
handlebars.js_projecthandlebars.js
1.0.8
handlebars.js_projecthandlebars.js
1.0.9
handlebars.js_projecthandlebars.js
1.0.10
handlebars.js_projecthandlebars.js
1.0.11
handlebars.js_projecthandlebars.js
1.0.12
handlebars.js_projecthandlebars.js
1.1.0
handlebars.js_projecthandlebars.js
1.1.1
handlebars.js_projecthandlebars.js
1.1.2
handlebars.js_projecthandlebars.js
1.2.0
handlebars.js_projecthandlebars.js
1.2.1
handlebars.js_projecthandlebars.js
1.3.0
handlebars.js_projecthandlebars.js
2.0.0
handlebars.js_projecthandlebars.js
3.0.0
handlebars.js_projecthandlebars.js
3.0.1
handlebars.js_projecthandlebars.js
3.0.2
handlebars.js_projecthandlebars.js
3.0.3
handlebars.js_projecthandlebars.js
3.0.4
handlebars.js_projecthandlebars.js
3.0.5
handlebars.js_projecthandlebars.js
3.0.6
handlebars.js_projecthandlebars.js
3.0.7
handlebars.js_projecthandlebars.js
4.0.0
handlebars.js_projecthandlebars.js
4.0.1
handlebars.js_projecthandlebars.js
4.0.2
handlebars.js_projecthandlebars.js
4.0.3
handlebars.js_projecthandlebars.js
4.0.4
handlebars.js_projecthandlebars.js
4.0.5
handlebars.js_projecthandlebars.js
4.0.6
handlebars.js_projecthandlebars.js
4.0.7
handlebars.js_projecthandlebars.js
4.0.8
handlebars.js_projecthandlebars.js
4.0.9
handlebars.js_projecthandlebars.js
4.0.10
handlebars.js_projecthandlebars.js
4.0.11
handlebars.js_projecthandlebars.js
4.0.12
handlebars.js_projecthandlebars.js
4.0.13
handlebars.js_projecthandlebars.js
4.0.14
handlebars.js_projecthandlebars.js
4.1.0
handlebars.js_projecthandlebars.js
4.1.1
handlebars.js_projecthandlebars.js
4.1.2
handlebars.js_projecthandlebars.js
4.2.0
handlebars.js_projecthandlebars.js
4.2.1
handlebars.js_projecthandlebars.js
4.2.2
tenabletenable.sc
𝑥
< 5.19.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-handlebars
bullseye
3:4.7.6+~4.1.0-2
fixed
bookworm
3:4.7.7+~4.1.0-1
fixed
sid
3:4.7.7+~4.1.0-1
fixed
trixie
3:4.7.7+~4.1.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-handlebars
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
ignored
disco
ignored
bionic
needs-triage
xenial
dne
trusty
dne