Prototype Pollution in handlebars.js - CVE-2021-23383
Published: May 10, 2021 / Updated: June 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when selecting certain compiling options to compile templates. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Red Hat OpenShift Container Platform
Nessus Network Monitor
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Netcool Operations Insight
openEuler
nodejs-handlebars
IBM InfoSphere Information Server
How to mitigate CVE-2021-23383
Red Hat OpenShift Container Platform - update to 4.6.36
Nessus Network Monitor - addressed in versions 6.2.0, 6.3.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
IBM Business Automation Workflow - addressed in versions 21.0.3-IF012, 22.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Netcool Operations Insight - update to 1.6.7
nodejs-handlebars - update to 4.0.13-2
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Links to Public Exploits and PoC-codes
External References
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031
- https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030
- https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029
Related Security Bulletins
- Remote code execution in handlebars.js
- Red Hat OpenShift Container Platform update for nodejs-handlebars
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Tenable Nessus Network Monitor update for third-party components
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- openEuler 20.03 LTS SP1 update for nodejs-handlebars
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation