Prototype Pollution in handlebars.js - CVE-2021-23383

 

Prototype Pollution in handlebars.js - CVE-2021-23383

Published: May 10, 2021 / Updated: June 29, 2021


Vulnerability identifier: #VU53013
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23383
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when selecting certain compiling options to compile templates. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

handlebars.js
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Nessus Network Monitor
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Netcool Operations Insight
openEuler
nodejs-handlebars
IBM InfoSphere Information Server

How to mitigate CVE-2021-23383

Install update from vendor's website.

handlebars.js - update to 4.7.7
Red Hat OpenShift Container Platform - update to 4.6.36
Nessus Network Monitor - addressed in versions 6.2.0, 6.3.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
IBM Business Automation Workflow - addressed in versions 21.0.3-IF012, 22.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Netcool Operations Insight - update to 1.6.7
nodejs-handlebars - update to 4.0.13-2
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins