Prototype pollution in handlebars.js - CVE-2019-19919
Published: July 22, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Affected software
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Tenable.sc
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Contrail Networking
Netcool Operations Insight
Operational Decision Manager
IBM InfoSphere Information Server
How to mitigate CVE-2019-19919
Tenable.sc - update to 5.19.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Contrail Networking - update to 1912
External References
Related Security Bulletins
- Prototype pollution in handlebars
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat Process Automation Manager 7.13
- Multiple vulnerabilities in Juniper Contrail Networking
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM MobileFirst Platform Foundation
- Multiple vulnerabilities in IBM Operational Decision Manager