Name | TEMP-0000000-345A3B |
Description | handlebars: quoteless attributes in templates can lead to content injection |
Source | Automatically generated temporary name. Not for external reference. |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
libjs-handlebars (PTS) | jessie | 1.3.0-1 | vulnerable |
| stretch | 3:4.0.5-4 | vulnerable |
ruby-handlebars-assets (PTS) | jessie | 0.15-2 | vulnerable |
| stretch/contrib | 2:0.23.1-1 | vulnerable |
| buster | 2:0.23.3+dfsg-2 | vulnerable |
| bullseye | 2:0.23.8+dfsg-3 | vulnerable |
| bookworm | 2:0.23.9+dfsg-1 | vulnerable |
| sid, trixie | 2:0.23.9+dfsg-2 | vulnerable |
The information below is based on the following data on fixed versions.
Notes
fixed in 4.0.0
https://blog.srcclr.com/handlebars_vulnerability_research_findings/
https://github.com/wycats/handlebars.js/pull/1083
https://nodesecurity.io/advisories/61
Security hardening, not a vulnerability