PT-2021-19955 · Hbs · Hbs
Agustin Gianni
+1
·
Published
2021-08-16
·
Updated
2022-07-02
·
CVE-2021-32822
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hbs (affected versions not specified)
Description
The hbs package, an Express view engine wrapper for Handlebars, may be vulnerable to a file disclosure issue depending on its usage. This occurs because hbs combines pure template data with engine configuration options through the Express render API, allowing the overwrite of internal configuration options. This can trigger a file disclosure vulnerability in downstream applications.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hbs