PT-2021-19954 · Unknown · Express-Handlebars

Agustin Gianni

+1

·

Published

2021-05-14

·

Updated

2024-03-06

·

CVE-2021-32820

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Express-handlebars (affected versions not specified)
Description The layout parameter in Express-handlebars may trigger file disclosure vulnerabilities in downstream applications, allowing inclusion of files with existing extensions. Files without extensions will have .handlebars appended to them. This issue is related to the mixing of pure template data with engine configuration options through the Express render API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-HANDLEBARS-2021-32820
CVE-2021-32820
GHSA-FR76-2WP8-FP92

Affected Products

Express-Handlebars