Cross-site scripting in handlebars - CVE-2019-20920
Published: January 5, 2020 / Updated: July 4, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Netcool Operations Insight
How to mitigate CVE-2019-20920
Red Hat OpenShift Container Platform - update to 4.6.36
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
External References
Related Security Bulletins
- Multiple vulnerabilities in handlebars package for Node.js
- Red Hat OpenShift Container Platform update for nodejs-handlebars
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation