valdisiljuconoks / optimizely-advanced-contentarea

Optimizely content area renderer on steroids
Apache License 2.0
34 stars 14 forks source link

WS-2019-0103 (Medium) detected in handlebars-1.3.0.tgz #56

Closed mend-bolt-for-github[bot] closed 3 years ago

mend-bolt-for-github[bot] commented 5 years ago

WS-2019-0103 - Medium Severity Vulnerability

Vulnerable Library - handlebars-1.3.0.tgz

Handlebars provides the power necessary to let you build semantic templates effectively with no frustration

Library home page: https://registry.npmjs.org/handlebars/-/handlebars-1.3.0.tgz

Path to dependency file: /tmp/WhiteSource-ArchiveExtractor_41c0e688-d421-4ea5-a1a5-8c862992cfd1/20190702203750_36821/git_depth_0/EPiBootstrapArea/src/EPiBootstrapArea.Forms/modules/_protected/Shell/Shell/11.1.0.0/ClientResources/lib/xstyle/package.json

Path to vulnerable library: /tmp/WhiteSource-ArchiveExtractor_41c0e688-d421-4ea5-a1a5-8c862992cfd1/20190702203750_36821/git_depth_0/EPiBootstrapArea/src/EPiBootstrapArea.Forms/modules/_protected/Shell/Shell/11.1.0.0/ClientResources/lib/xstyle/node_modules/handlebars/package.json

Dependency Hierarchy: - intern-geezer-2.2.3.tgz (Root Library) - istanbul-0.2.16.tgz - :x: **handlebars-1.3.0.tgz** (Vulnerable Library)

Found in HEAD commit: bc457a9f9b325b3aac41f3b4fa094e51c068820b

Vulnerability Details

Handlebars.js before 4.1.0 has Remote Code Execution (RCE)

Publish Date: 2019-05-30

URL: WS-2019-0103

CVSS 2 Score Details (5.5)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://github.com/wycats/handlebars.js/commit/edc6220d51139b32c28e51641fadad59a543ae57

Release Date: 2019-05-30

Fix Resolution: 4.0.13


Step up your Open Source Security Game with WhiteSource here