CVE-2019-20922
Summary
| CVE | CVE-2019-20922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-30 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Handlebarsjs | Handlebars | All | All | All | All |
| Application | Handlebarsjs | Handlebars | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: non-eager matching raw-block-contents · handlebars-lang/handlebars.js@8d5530e · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Denial of Service (DoS) in handlebars | Snyk | MISC | snyk.io | Third Party Advisory |
| Overview | MISC | www.npmjs.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.