CVE-2021-23369: Remote Code Execution (RCE)
A flaw was found in nodejs-handlebars. A missing check when getting prototype properties in the template function allows an attacker, who can provide untrusted handlebars templates, to execute arbitrary code in the javascript system (e.g. browser or server) when the template is compiled with the strict:true option. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23369.
What is the severity of CVE-2021-23369?
CVE-2021-23369 has a severity score of 9.8 (Critical).
What is the affected software for CVE-2021-23369?
The affected software for CVE-2021-23369 is handlebars version up to 4.7.7.
How can an attacker exploit CVE-2021-23369?
An attacker can exploit CVE-2021-23369 by providing untrusted handlebars templates, which allows them to execute arbitrary code in the JavaScript system when the template is compiled with the vulnerable handlebars version.
How can I fix CVE-2021-23369?
To fix CVE-2021-23369, update handlebars to version 4.7.7.