QID 996084
Date Published: 2023-11-28
QID 996084: Rubygems (Rubygems) Security Update for bootstrap-wysihtml5-rails (GHSA-w457-6q6x-cgp9)
Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w457-6q6x-cgp9 for updates and patch information.
Vendor References
- GHSA-w457-6q6x-cgp9 -
github.com/advisories/GHSA-w457-6q6x-cgp9
CVEs related to QID 996084
Software Advisories
| Advisory ID | Software | Component | Link |
|---|