Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-32822
HistoryAug 16, 2021 - 7:15 p.m.

Arbitrary file deletion

2021-08-1619:15:00
PRIOn knowledge base
www.prio-n.com
5

5.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.4%

The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options a file disclosure vulnerability may be triggered in downstream applications. For an example PoC see the referenced GHSL-2021-020.

5.3 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.4%

Related for PRION:CVE-2021-32822