View Categories

Handlebars – Template Injection And Remote Code Execution On Versions Under 4.6.0

Table of Contents

Impact area

Security

Severity

High

Affected element

ServiceNow

UI Script

Salesforce

Static Resource

Rule number #

SN-JSL-HANDLEBARS-LESSTHAN-V460 (for ServiceNow)

SF-JSL-HANDLEBARS-LESSTHAN-V460 (for Salesforce)

Impact #

Templates may alter an Objects’ prototype, thus allowing an attacker to execute arbitrary code on the server.

Remediation

Update the Handlebars JS library to the latest version.

Time to fix

30 min

References #

This rule is linked to Common Weakness Enumeration CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’).

Powered by BetterDocs