Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remediate High handlebars vulnerability #672

Open
Lilalamar opened this issue Jan 29, 2020 · 0 comments
Open

Remediate High handlebars vulnerability #672

Lilalamar opened this issue Jan 29, 2020 · 0 comments
Assignees
Labels
security Ticket concerns platform security

Comments

@Lilalamar
Copy link

GitHub reports the following High severity vulnerability in HumanCellAtlas/ingest-validator, HumanCellAtlas/ingest-validator-js and HumanCellAtlas/ingest-file-archiver. Please remediate by the end of Q1 Milestone 2.

Description
handlebars

Suggested Remediation
Upgrade handlebars to version 4.3.0 or later.

Details
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's proto and defineGetter properties, which may allow an attacker to execute arbitrary code through crafted payloads.

@Lilalamar Lilalamar added the security Ticket concerns platform security label Jan 29, 2020
@Lilalamar Lilalamar added this to the Q1 2020 Milestone 2 milestone Jan 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Ticket concerns platform security
Projects
None yet
Development

No branches or pull requests

2 participants