CVE-2019-20922

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
Configurations

Configuration 1 (hide)

cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2020-09-30 18:15

Updated : 2024-02-04 21:23


NVD link : CVE-2019-20922

Mitre link : CVE-2019-20922

CVE.ORG link : CVE-2019-20922


JSON object : View

Products Affected

handlebarsjs

  • handlebars
CWE
CWE-400

Uncontrolled Resource Consumption