Infinite loop in handlebars - CVE-2019-20922
Published: January 6, 2020 / Updated: July 4, 2021
Vulnerability identifier: #VU23982
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20922
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing specially-crafted templates. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
handlebars
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Netcool Operations Insight
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Netcool Operations Insight
How to mitigate CVE-2019-20922
Update to version 4.4.5.
handlebars - update to 4.4.5
Red Hat OpenShift Container Platform - update to 4.6.36
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
Red Hat OpenShift Container Platform - update to 4.6.36
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
External References
Related Security Bulletins
- Infinite loop in handlebars package for Node.js
- Red Hat OpenShift Container Platform update for nodejs-handlebars
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation