7.5
CVSSv2

CVE-2019-19919

Published: 20/12/2019 Updated: 03/06/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Versions of handlebars before 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an malicious user to execute arbitrary code through crafted payloads.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

handlebars.js project handlebars.js 1.0.6

handlebars.js project handlebars.js 1.0.7

handlebars.js project handlebars.js 1.0.8

handlebars.js project handlebars.js 1.0.9

handlebars.js project handlebars.js 1.0.10

handlebars.js project handlebars.js 1.0.11

handlebars.js project handlebars.js 1.0.12

handlebars.js project handlebars.js 1.1.0

handlebars.js project handlebars.js 1.1.1

handlebars.js project handlebars.js 1.1.2

handlebars.js project handlebars.js 1.2.0

handlebars.js project handlebars.js 1.2.1

handlebars.js project handlebars.js 1.3.0

handlebars.js project handlebars.js 2.0.0

handlebars.js project handlebars.js 3.0.0

handlebars.js project handlebars.js 3.0.1

handlebars.js project handlebars.js 3.0.2

handlebars.js project handlebars.js 3.0.3

handlebars.js project handlebars.js 4.0.0

handlebars.js project handlebars.js 4.0.1

handlebars.js project handlebars.js 4.0.2

handlebars.js project handlebars.js 4.0.3

handlebars.js project handlebars.js 4.0.4

handlebars.js project handlebars.js 4.0.5

handlebars.js project handlebars.js 4.0.6

handlebars.js project handlebars.js 4.0.7

handlebars.js project handlebars.js 4.0.8

handlebars.js project handlebars.js 4.0.9

handlebars.js project handlebars.js 4.0.10

handlebars.js project handlebars.js 4.0.11

handlebars.js project handlebars.js 3.0.4

handlebars.js project handlebars.js 3.0.5

handlebars.js project handlebars.js 3.0.6

handlebars.js project handlebars.js 3.0.7

handlebars.js project handlebars.js 4.0.12

handlebars.js project handlebars.js 4.0.13

handlebars.js project handlebars.js 4.0.14

handlebars.js project handlebars.js 4.1.0

handlebars.js project handlebars.js 4.1.1

handlebars.js project handlebars.js 4.1.2

handlebars.js project handlebars.js 4.2.0

handlebars.js project handlebars.js 4.2.1

handlebars.js project handlebars.js 4.2.2

tenable tenable.sc

Vendor Advisories

Synopsis Critical: Red Hat Process Automation Manager 7132 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) base score, which gi ...
Tenablesc leverages third-party software to help provide underlying functionality Multiple third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of the ...