---
title: "CVE-2021-23369"
canonical: "https://kb.cynergy.app/space/MD/899285404/CVE-2021-23369"
format: markdown
---
**Description**

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

**Published On**

2021-04-12

**Updated On**

2021-06-08

**Trending**

FALSE

**Mitigation:**

![image](media://1bc40223-b158-4d9d-a70b-68178ed30e44)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| RHSA-2021:2500 | redhat | Red Hat Security Advisory: Red Hat OpenShift Enterprise security and bug fix update | Red Hat OpenShift Container Platform release 4.6.36 is now available with  
updates to packages and images that fix several bugs and add enhancements.<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2021-06-30 | [https://access.redhat.com/errata/RHSA-2021:2500](https://access.redhat.com/errata/RHSA-2021:2500) |
| RHSA-2021:3016 | redhat | Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes version 2.3 | Red Hat Advanced Cluster Management for Kubernetes 2.3.0 General  
Availability release images, which fix several bugs and security issues.<br>Red Hat Product Security has rated this update as having a security impact  
of Important. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability  
from the CVE links in the References section. | 2021-08-25 | [https://access.redhat.com/errata/RHSA-2021:3016](https://access.redhat.com/errata/RHSA-2021:3016) |
| RHSA-2021:4032 | redhat | Red Hat Security Advisory: Openshift Logging 5.2.3 bug fix and security update | An update is now available for OpenShift Logging 5.2.<br>Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-11-18 | [https://access.redhat.com/errata/RHSA-2021:4032](https://access.redhat.com/errata/RHSA-2021:4032) |
| RHSA-2021:4628 | redhat | Red Hat Security Advisory: Openshift Logging 5.1.4 bug fix and security update | An update is now available for OpenShift Logging 5.1.4.<br>Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-11-18 | [https://access.redhat.com/errata/RHSA-2021:4628](https://access.redhat.com/errata/RHSA-2021:4628) |