Bug 1789959 (CVE-2019-19919)
| Summary: | CVE-2019-19919 nodejs-handlebars: prototype pollution leading to remote code execution via crafted payloads | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | alazarot, bdettelb, bmontgom, dominik.mierzejewski, e, emingora, eparis, etirelli, ibek, jburrell, jcantril, jrokos, kverlaen, mnovotny, nodejs-sig, nstielau, piotr1212, pjindal, rguimara, rrajasek, sponnaga, tomckay, tzimanyi |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | nodejs-handlebars-4.3.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in nodejs-handlebars, where it is vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which allows an attacker to execute arbitrary code through crafted payloads. The highest threat from this vulnerability is to confidentiality and integrity.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-03-20 13:31:04 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1957625, 1957626, 1957627, 1789960, 1789961, 1789962, 1790773, 1790775, 1790776, 1790777, 1790778 | ||
| Bug Blocks: | 1789963 | ||
|
Description
Guilherme de Almeida Suckevicz
2020-01-10 20:34:15 UTC
Created nodejs-handlebars tracking bugs for this issue: Affects: epel-6 [bug 1789961] Affects: epel-7 [bug 1789962] Affects: fedora-all [bug 1789960] i really wonder about CVE bugs getting reported since a year for various packages related to me. First they got reported then priority set low then discovered not present in one by one distribution and then get closed..... While OpenShift Container Platform (OCP) contains the affected nodejs-handlebars code, it's added as a dependency of Kibana 5. Similar issue about prototype pollution [1] have been fixed, but no known attack vector was found, so we're rating this issue as Low for OCP. [1] CVE-2019-10744 https://www.elastic.co/community/security While Red Hat Quay declares a dependency on nodejs-handlebars, it doesn't appear to be used in the code. This issue might be fixed in a future update. Statement: Red Hat Quay includes Handlebars.js as a development dependency. It does not use Handlebars.js at runtime to process templates so have been given a low impact rating. This issue has been addressed in the following products: Red Hat Process Automation Via RHSA-2023:1334 https://access.redhat.com/errata/RHSA-2023:1334 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-19919 |