Code Injection in handlebars.js - CVE-2021-23369

 

Code Injection in handlebars.js - CVE-2021-23369

Published: February 23, 2021 / Updated: July 4, 2021


Vulnerability identifier: #VU50896
CSH Severity: High
CVSS v4 BT: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2021-23369
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

handlebars.js
IBM Watson Machine Learning Accelerator
IBM Business Automation Manager Open Editions
MobileFirst Platform
Centreon
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat OpenShift Container Platform
Nessus Network Monitor
Oracle WebLogic Server
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Netcool Operations Insight

How to mitigate CVE-2021-23369

Install updates from vendor's website.

handlebars.js - update to 4.7.7
Centreon - addressed in versions 2.8.36, 19.10.20
Red Hat OpenShift Container Platform - update to 4.6.36
Nessus Network Monitor - addressed in versions 6.2.0, 6.3.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
IBM Business Automation Workflow - addressed in versions 21.0.3-IF012, 22.0.1-IF002
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Netcool Operations Insight - update to 1.6.7
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031

External References

Related Security Bulletins