-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed #189
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Chore
ContributorsCommit-Lint commandsYou can trigger Commit-Lint actions by commenting on this PR:
|
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.5.3 [security]
chore(deps): update dependency handlebars to 4.7.7 [security]
May 9, 2021
renovate
bot
force-pushed
the
renovate/npm-handlebars-vulnerability
branch
from
March 7, 2022 15:43
663d4c2
to
a50e17e
Compare
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - abandoned
Mar 25, 2023
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - abandoned
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 25, 2023
renovate
bot
force-pushed
the
renovate/npm-handlebars-vulnerability
branch
from
March 25, 2023 05:14
a50e17e
to
5e9ea21
Compare
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 25, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 25, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 27, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 28, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 28, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 28, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 28, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 31, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 31, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Mar 31, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Mar 31, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Apr 1, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Apr 3, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Apr 3, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
Apr 17, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
chore(deps): update dependency handlebars to 4.7.7 [security]
Apr 18, 2023
renovate
bot
changed the title
chore(deps): update dependency handlebars to 4.7.7 [security]
chore(deps): update dependency handlebars to 4.7.7 [security] - autoclosed
May 28, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.11
->4.7.7
GitHub Vulnerability Alerts
GHSA-q42p-pg8m-cqh6
Versions of
handlebars
prior to 4.0.14 are vulnerable to Prototype Pollution. Templates may alter an Objects' prototype, thus allowing an attacker to execute arbitrary code on the server.Recommendation
For handlebars 4.1.x upgrade to 4.1.2 or later.
For handlebars 4.0.x upgrade to 4.0.14 or later.
CVE-2019-19919
Versions of
handlebars
prior to 3.0.8 or 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Objects'__proto__
and__defineGetter__
properties, which may allow an attacker to execute arbitrary code through crafted payloads.Recommendation
Upgrade to version 3.0.8, 4.3.0 or later.
GHSA-2cf5-4w76-r9qv
Versions of
handlebars
prior to 3.0.8 or 4.5.2 are vulnerable to Arbitrary Code Execution. The package's lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system. It can be used to run arbitrary code in a server processing Handlebars templates or on a victim's browser (effectively serving as Cross-Site Scripting).The following template can be used to demonstrate the vulnerability:
Recommendation
Upgrade to version 3.0.8, 4.5.2 or later.
GHSA-q2c6-c6pm-g3gh
Versions of
handlebars
prior to 3.0.8 or 4.5.3 are vulnerable to Arbitrary Code Execution. The package's lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript in the system. It is due to an incomplete fix for a previous issue. This vulnerability can be used to run arbitrary code in a server processing Handlebars templates or on a victim's browser (effectively serving as Cross-Site Scripting).Recommendation
Upgrade to version 3.0.8, 4.5.3 or later.
GHSA-g9r4-xpmj-mj65
Versions of
handlebars
prior to 3.0.8 or 4.5.3 are vulnerable to prototype pollution. It is possible to add or modify properties to the Object prototype through a malicious template. This may allow attackers to crash the application or execute Arbitrary Code in specific conditions.Recommendation
Upgrade to version 3.0.8, 4.5.3 or later.
CVE-2021-23369
The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2019-20920
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).
CVE-2021-23383
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.