Vulnerability DatabaseGHSA-2cf5-4w76-r9qv

GHSA-2cf5-4w76-r9qv
JavaScript vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-2cf5-4w76-r9qv) affects the Handlebars npm package, discovered and published to the GitHub Advisory Database on September 4, 2020. This high-severity vulnerability impacts versions prior to 3.0.8 and versions between 4.0.0 and 4.5.2 of the Handlebars package (GitHub Advisory).

Technical details

The vulnerability is classified as an Arbitrary Code Execution issue with a CVSS score of 7.3 (High). The package's lookup helper contains a validation flaw in templates that allows attackers to execute arbitrary JavaScript code. The CVSS base metrics indicate a Local attack vector, Low attack complexity, Low privileges required, Required user interaction, Changed scope, Low confidentiality impact, High integrity impact, and Low availability impact (GitHub Advisory).

Impact

When exploited, this vulnerability enables attackers to execute arbitrary code either on a server processing Handlebars templates or on a victim's browser, effectively serving as a Cross-Site Scripting attack vector. The vulnerability has particularly high impact on system integrity while maintaining lower impacts on confidentiality and availability (GitHub Advisory).

Exploitability

The vulnerability can be exploited through specially crafted templates that bypass the lookup helper's validation. A proof-of-concept template has been documented that demonstrates the vulnerability by executing JavaScript alerts (GitHub Advisory).

Mitigation and workarounds

Users are strongly recommended to upgrade to the patched versions: either version 3.0.8 or version 4.5.2 or later, depending on their current version track. These versions contain fixes that address the template validation vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-43309HIGH7.5
  • JavaScript logoJavaScript
  • uri-template-lite
NoYesAug 24, 2022
CVE-2022-24375HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 24, 2022
CVE-2022-25231HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-21208HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-2932MEDIUM6.1
  • JavaScript logoJavaScript
  • mobiledoc-kit
NoYesAug 22, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management