This repository was archived by the owner on Sep 21, 2022. It is now read-only.
Update dependency express-handlebars to v5 [SECURITY]#507
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 11, 2022 02:12
6700671 to
e0ca83d
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 11, 2022 08:01
e0ca83d to
57a0644
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 11, 2022 09:51
57a0644 to
e09db59
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 13, 2022 10:15
e09db59 to
3de95ff
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 13, 2022 11:57
3de95ff to
4240e2f
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 15, 2022 12:28
4240e2f to
a5a8939
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 15, 2022 14:13
a5a8939 to
c57a4e6
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 16, 2022 09:32
c57a4e6 to
db1bd59
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 16, 2022 11:41
db1bd59 to
f588473
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 17, 2022 09:12
f588473 to
30ba040
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 23, 2022 13:58
3a24feb to
791930f
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 23, 2022 15:41
791930f to
f7fe660
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 23, 2022 21:53
f7fe660 to
8bb6358
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 23, 2022 23:50
8bb6358 to
125a785
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 24, 2022 18:21
125a785 to
83b4a5a
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 24, 2022 20:35
83b4a5a to
0420d39
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 27, 2022 09:12
0420d39 to
7d4178e
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 27, 2022 11:02
7d4178e to
cf12de3
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 27, 2022 12:47
cf12de3 to
747e6a8
Compare
renovate
Bot
force-pushed
the
renovate/npm-express-handlebars-vulnerability
branch
from
February 27, 2022 14:19
747e6a8 to
ef7a013
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.4->^5.0.0GitHub Vulnerability Alerts
CVE-2021-32820
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat restricted in that only files with existing extentions (i.e. file.extension) can be included, files that lack an extension will have .handlebars appended to them. For complete details refer to the referenced GHSL-2021-018 report. Notes in documentation have been added to help users avoid this potential information exposure vulnerability.
A fix is discussed in https://github.com/express-handlebars/express-handlebars/pull/163
Release Notes
express-handlebars/express-handlebars
v5.3.1Compare Source
Bug Fixes
v5.3.0Compare Source
Features
5.2.1 (2021-02-16)
Bug Fixes
v5.2.1Compare Source
Bug Fixes
v5.2.0Compare Source
Features
v5.1.0Compare Source
Features
v5.0.0Compare Source
Bug Fixes
BREAKING CHANGES
4.0.6 (2020-07-06)
Bug Fixes
4.0.5 (2020-07-03)
Bug Fixes
4.0.4 (2020-04-29)
Bug Fixes
4.0.3 (2020-04-05)
Bug Fixes
4.0.2 (2020-04-03)
Bug Fixes
Configuration
📅 Schedule: "" (UTC).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by WhiteSource Renovate. View repository job log here.