Lucene search

K
osvGoogleOSV:CVE-2019-20922
HistorySep 30, 2020 - 6:15 p.m.

CVE-2019-20922

2020-09-3018:15:18
Google
osv.dev
10
handlebars
redos
vulnerability
parser
crafted templates
system resources

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

56.6%

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

56.6%