CVE-2019-19919

Description

Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
17.796

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.0.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.4Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10.5.2Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.12.0.1Windows
Vulnerabilities CVE-2019-19919 are affected in Ruby-bootstrap-wysihtml5-rails 0.3.3.8Windows
Vulnerabilities CVE-2019-19919 are affected in Ruby-bootstrap-wysihtml5-rails for Linux 0.3.3.8Linux
Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) Vulnerability (CVE-2019-19919)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234