Uploaded image for project: 'Network Controller'
  1. Network Controller
  2. SDNC-602

Security vulnerability in handlebars javascript package

XMLWordPrintable

    • SDNC Dublin Spr 3 3/11 - 3/29, SDNC Fr Sp2:11/23-12/13

      The handlebars.js script is vulnerable to a cross site scripting (XSS) vulnerability, due to the fact that its escapeExpression class does not properly escape the equal (=) sign.

      This only occurs when double curly braces {{}} are used (as opposed to triple, which does no escaping).  

      This appears to be fixed in version 4.0.0 and above.

      See https://github.con/wycats/handlebars.js/pull/1083

            Unassigned Unassigned
            djtimoney Dan Timoney
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: