Search CVE reports
311 – 320 of 42765 results
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause...
1 affected package
node-handlebars
| Package | 18.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the...
1 affected package
node-handlebars
| Package | 18.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within...
1 affected package
node-handlebars
| Package | 18.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a...
1 affected package
node-handlebars
| Package | 18.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials`...
1 affected package
node-handlebars
| Package | 18.04 LTS |
|---|---|
| node-handlebars | Needs evaluation |
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
1 affected package
varnish
| Package | 18.04 LTS |
|---|---|
| varnish | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...
1 affected package
netty
| Package | 18.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...
1 affected package
netty
| Package | 18.04 LTS |
|---|---|
| netty | Needs evaluation |
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates...
1 affected package
undertow
| Package | 18.04 LTS |
|---|---|
| undertow | Needs evaluation |
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header...
1 affected package
undertow
| Package | 18.04 LTS |
|---|---|
| undertow | Needs evaluation |