VDB
CVE-2021-23369
CVE-2021-23369
PUBLISHED
CVSS 5.599999904632568 MEDIUM
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
EPSS 7.03% · 94.0th percentile
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
7.03%
94.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | node-handlebars | 3:4.0.10-5, 0 |
| Ubuntu:20.04:LTS | node-handlebars | 3:4.1.0-1, 0, 3:4.7.2-1 |
| Ubuntu:22.04:LTS | node-handlebars | 3:4.7.6+~4.1.0-2, 0, 3:4.7.7+~4.1.0-1 |
Timeline
- Oct 23, 2018 PoC Published
- Apr 12, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 23, 2023 EPSS Score
- Jul 5, 2023 EPSS Score
- Nov 17, 2023 EPSS Score
- Feb 19, 2024 EPSS Score
- Apr 15, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
- Mar 17, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-23369 third-party-advisory
- https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8 third-party-advisory
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427 third-party-advisory
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767 third-party-advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950 third-party-advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951 third-party-advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-23369 third-party-advisory