CVE-2019-20922: High severity Handlebarsjs Handlebars Node.js vulnerability
A flaw was found in nodejs-handlebars, where affected versions of handlebars are vulnerable to a denial of service. The package's parser may be forced into an endless loop while processing specially-crafted templates. This flaw allows attackers to exhaust system resources, leading to a denial of service.
Other sources
Affected versions of handlebars are vulnerable to Denial of Service. The package's parser may be forced into an endless loop while processing specially-crafted templates. This may allow attackers to exhaust system resources leading to Denial of Service.
Reference:
https://www.npmjs.com/advisories/1300
— Red Hat
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-20922?
CVE-2019-20922 is a vulnerability that allows Regular Expression Denial of Service (ReDoS) in Handlebars before version 4.4.5.
What is the severity of CVE-2019-20922?
CVE-2019-20922 has a severity rating of high, with a severity value of 7.
How does CVE-2019-20922 affect Handlebars?
CVE-2019-20922 affects Handlebars versions before 4.4.5 and can cause a denial of service by forcing the package's parser into an endless loop while processing specially-crafted templates.
How can I fix CVE-2019-20922 in Handlebars?
To fix CVE-2019-20922 in Handlebars, update to version 4.4.5 or later.
Where can I find more information about CVE-2019-20922?
You can find more information about CVE-2019-20922 at the following references: [CVE-2019-20922](https://www.cve.org/CVERecord?id=CVE-2019-20922), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-20922), [npmjs](https://www.npmjs.com/advisories/1300), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1882256), [Red Hat Advisory RHSA-2021:2500](https://access.redhat.com/errata/RHSA-2021:2500).