Lucene search

K
ubuntucveUbuntu.comUB:CVE-2019-20922
HistorySep 30, 2020 - 12:00 a.m.

CVE-2019-20922

2020-09-3000:00:00
ubuntu.com
ubuntu.com
22
handlebars
regular expression denial
eager matching
endless loop
crafted templates
system resources
unix

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.6%

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS)
because of eager matching. The parser may be forced into an endless loop
while processing crafted templates. This may allow attackers to exhaust
system resources.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnode-handlebars< anyUNKNOWN

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

56.6%