This repository has been archived by the owner on Feb 22, 2021. It is now read-only.
WS-2019-0103 (Medium) detected in handlebars-2.0.0.tgz #271
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0103 - Medium Severity Vulnerability
Vulnerable Library - handlebars-2.0.0.tgz
Handlebars provides the power necessary to let you build semantic templates effectively with no frustration
Library home page: https://registry.npmjs.org/handlebars/-/handlebars-2.0.0.tgz
Path to dependency file: /apollo/ui/package.json
Path to vulnerable library: /tmp/git/apollo/ui/node_modules/handlebars/package.json
Dependency Hierarchy:
Found in HEAD commit: 027c477d78c1b2eaf58b4277c1fc19c405b8e1f6
Vulnerability Details
Handlebars.js before 4.1.0 has Remote Code Execution (RCE)
Publish Date: 2019-05-30
URL: WS-2019-0103
CVSS 2 Score Details (5.5)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: handlebars-lang/handlebars.js@edc6220
Release Date: 2019-05-30
Fix Resolution: 4.0.13
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: