Prototype Pollution In bootstrap-wysihtml5-rails
Description
Prototype Pollution in handlebars
Versions of handlebars prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects' __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Recommendation
Upgrade to version 3.0.8, 4.3.0 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | - | ||
debian 14 | 3:4.5.3-1 | ||
npm | 4.3.0, 3.0.8 | ||
debian 13 | 3:4.5.3-1 | ||
debian 12 | 3:4.5.3-1 | ||
debian 11 | 3:4.5.3-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.