rstudio / shiny-server

Host Shiny applications over the web.
https://rstudio.com/shiny/server
Other
712 stars 290 forks source link

Critical and High Vulnerabilities in Shiny Server 1.5.16.958 #483

Closed dvasilen closed 3 years ago

dvasilen commented 3 years ago

Critical Vulnerabilities

  1. CVE-2021-23369 /opt/shiny-server/node_modules/handlebars

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

High Vulnerabilities

  1. CVE-2021-23358 /opt/shiny-server/node_modules/underscore

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

johnstacy commented 3 years ago

While you're at it...

Not to mention other less severe vulnerabilities: