QID 981257
QID 981257: Nodejs (npm) Security Update for hbs (GHSA-7f5c-rpf4-86p8)
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options a file disclosure vulnerability may be triggered in downstream applications. For an example PoC see the referenced GHSL-2021-020.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7f5c-rpf4-86p8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7f5c-rpf4-86p8 -
github.com/advisories/GHSA-7f5c-rpf4-86p8
CVEs related to QID 981257
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7f5c-rpf4-86p8 | hbs |
|