Infinite loop in handlebars - CVE-2019-20922

 

Infinite loop in handlebars - CVE-2019-20922

Published: January 6, 2020 / Updated: July 4, 2021


Vulnerability identifier: #VU23982
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20922
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when processing specially-crafted templates. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

handlebars
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Netcool Operations Insight

How to mitigate CVE-2019-20922

Update to version 4.4.5.

handlebars - update to 4.4.5
Red Hat OpenShift Container Platform - update to 4.6.36
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031

External References

Related Security Bulletins