Prototype pollution in handlebars.js - CVE-2019-19919

 

Prototype pollution in handlebars.js - CVE-2019-19919

Published: July 22, 2021


Vulnerability identifier: #VU55264
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19919
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.


Affected software

handlebars.js
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Tenable.sc
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Contrail Networking
Netcool Operations Insight
Operational Decision Manager
IBM InfoSphere Information Server

How to mitigate CVE-2019-19919

Install update from vendor's website.

handlebars.js - update to 4.3.0
Tenable.sc - update to 5.19.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Contrail Networking - update to 1912

External References

Related Security Bulletins