CVE-2019-20922

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*

Information

Published : 2020-09-30 11:15

Updated : 2021-07-21 04:39


NVD link : CVE-2019-20922

Mitre link : CVE-2019-20922


JSON object : View

CWE
CWE-400

Uncontrolled Resource Consumption

Advertisement

dedicated server usa

Products Affected

handlebarsjs

  • handlebars