
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-0323 is a vulnerability identified in Packagist mustache/mustache versions prior to 2.14.1, involving improper neutralization of special elements used in a template engine. The vulnerability was discovered and disclosed in January 2022, affecting the PHP implementation of Mustache templating system (NVD).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code - 'Code Injection') and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). It received a CVSS v3.1 base score of 8.8 (HIGH) from NVD with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, while huntr.dev assessed it with a CVSS score of 5.3 (MEDIUM) (NVD).
The vulnerability could potentially lead to Remote Code Execution (RCE) when rendering untrusted user templates, allowing attackers to execute arbitrary code on affected systems (GitHub Patch).
The vulnerability has been patched in version 2.14.1 of mustache/mustache. Users should upgrade to this version or later to mitigate the risk. The fix involves proper neutralization of section names and removal of unnecessary comments in generated source code (GitHub Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."