brightcove / videojs-dock

Obsolete and no longer maintained, equivalent functionality will become a feature of Video.js itself in 8.0!
http://brightcove.github.io/videojs-dock/
Other
17 stars 11 forks source link

WS-2019-0103 (Medium) detected in handlebars-4.0.12.tgz #109

Closed mend-for-github-com[bot] closed 2 years ago

mend-for-github-com[bot] commented 2 years ago

WS-2019-0103 - Medium Severity Vulnerability

Vulnerable Library - handlebars-4.0.12.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-4.0.12.tgz

Path to dependency file: videojs-dock/package.json

Path to vulnerable library: videojs-dock/node_modules/handlebars/package.json

Dependency Hierarchy: - videojs-generate-karma-config-5.0.0.tgz (Root Library) - karma-coverage-1.1.2.tgz - istanbul-0.4.5.tgz - :x: **handlebars-4.0.12.tgz** (Vulnerable Library)

Found in HEAD commit: 94e6200be9ecc48ffad7dd009fa94bbfc47f0391

Found in base branch: main

Vulnerability Details

Handlebars.js before 4.1.0 has Remote Code Execution (RCE)

Publish Date: 2019-01-30

URL: WS-2019-0103

CVSS 3 Score Details (5.6)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: High - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/wycats/handlebars.js/commit/edc6220d51139b32c28e51641fadad59a543ae57

Release Date: 2019-01-30

Fix Resolution: 4.1.0