CVE-2019-20922

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
Configurations

Configuration 1

cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:*

Information

Published : 2020-09-30 06:15

Updated : 2021-07-21 11:39


NVD link : CVE-2019-20922

Mitre link : CVE-2019-20922

Products Affected
No products.
CWE