godaddy-wordpress / godaddy-wordpress/lumiere

CVE-2022-40313 (High) detected in mustache/mustache-v2.14.2

Open
#31 0 comments 0 reactions 0 assignees View on GitHub
security vulnerability
Dominant language
PHP
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

## CVE-2022-40313 - High Severity Vulnerability
Vulnerable Library - mustache/mustache-v2.14.2

A Mustache implementation in PHP.


Library home page: https://api.github.com/repos/bobthecow/mustache.php/zipball/e62b7c3849d22ec55f3ec425507bf7968193a6cb


Dependency Hierarchy:
- lucatume/wp-browser-3.1.6 (Root Library)
- wp-cli/wp-cli-v2.7.1
- :x: **mustache/mustache-v2.14.2** (Vulnerable Library)

Found in HEAD commit: b93c032745146ac3a2f902f2dab07a4e58d519a5


Found in base branch: master



Vulnerability Details



Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

Publish Date: 2022-09-30

URL: CVE-2022-40313



CVSS 3 Score Details (7.1)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://moodle.org/mod/forum/discuss.php?d=438392


Release Date: 2022-09-30


Fix Resolution: v3.9.17,v3.11.10,v4.0.4

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.