Skip to content

[Security] The included handlebars.js (v. 3.0.2) is affected by CVE-2019-19919 #161

@ddalcino

Description

@ddalcino

This gem includes an old version of handlebars (v 3.0.2), which includes a security bug fixed in v 4.3.0. I don't know if this gem is maintained anymore, but if it is I think it would be worthwhile to update handlebars to 4.3.0 or 3.0.8.

If this gem is not maintained anymore, maybe the README could warn users about this?

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19919
GHSA-w457-6q6x-cgp9

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions