---
title: "CVE-2022-0323"
canonical: "https://kb.cynergy.app/space/MD/923762709/CVE-2022-0323"
format: markdown
---
**Description**

Certain versions of [Mustache](https://cve.report/software/mustache_project/mustache) from [Mustache Project](https://cve.report/vendor/mustache_project) contain the following vulnerability:

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

 

**Published On**

01/21/2022

**Updated On**

08/08/2022

**Trending**

FALSE

**CWE**

<u>[CWE-1336](http://cwe.mitre.org/data/definitions/1336.html)</u>

**Exploit**

[https://huntr.dev/bounties/a5f5a988-aa52-4443-839d-299a63f44fb7/](https://huntr.dev/bounties/a5f5a988-aa52-4443-839d-299a63f44fb7/) 

**Mitigation:**

![image](media://ff275ef7-fd20-4344-a226-0c0988559651)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- FreeBSD has released a security update for mustache - possible remote code execution to fix the vulnerabilities Please update to the latest version

**Reference**

|  |  |  |
| --- | --- | --- |
| huntr – the Bug Bounty Platform for any GitHub repository | <span style="color: #ffffff">**huntr.dev**</span>  
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Fix CVE-2022-0323 (improper neutralization of section names) · bobthecow/mustache.php@579ffa5 · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |