VDB

CVE-2021-23369

CVE-2021-23369 PUBLISHED

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

EPSS 3.58% · 87.9th percentile

Risk Scores

EPSS Score
3.58%
87.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-handlebars3:4.0.10-5, 0
Ubuntu:20.04:LTSnode-handlebars3:4.1.0-1, 0, 3:4.7.2-1
Ubuntu:22.04:LTSnode-handlebars3:4.7.6+~4.1.0-2, 0, 3:4.7.7+~4.1.0-1

Timeline

  • Oct 23, 2018 PoC Published
  • Apr 12, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 9, 2021 CVE Updated
  • Feb 4, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 8, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score
  • Nov 17, 2023 EPSS Score
  • Feb 19, 2024 EPSS Score
  • Apr 15, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›