Name | TEMP-0000000-345A3B |
Description | handlebars: quoteless attributes in templates can lead to content injection |
Source | Automatically generated temporary name. Not for external reference. |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
ruby-handlebars-assets (PTS) | bullseye | 2:0.23.8+dfsg-3 | vulnerable |
| bookworm | 2:0.23.9+dfsg-1 | vulnerable |
| sid, trixie | 2:0.23.9+dfsg-2 | vulnerable |
The information below is based on the following data on fixed versions.
Notes
fixed in 4.0.0
https://blog.srcclr.com/handlebars_vulnerability_research_findings/
https://github.com/wycats/handlebars.js/pull/1083
https://nodesecurity.io/advisories/61
Security hardening, not a vulnerability