
amit.kumar36 (Community Member) asked a question.
Hi Team,
We recently did External Penetration Testing on our code repository and found that we are using Handlebars.js v4.0.2 in our application. Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Please help me understand why Veracode didn't found this flaw?
.png)
Hello @amit.kumar36 (Community Member) ,
Since you have uploaded a WAR file, it is possible that the compilation using the outlined structure was not valid. If this is the issue which is the compilation, then we may not have detected even if you included all the files. To ensure that the appropriate files are detected by SCA, it is important to follow the compilation instructions. If you need any further assistance with the packaging, you can speak to one of our Application Security Consultants for guidance on this. Please see second link below.
Topic: Packaging JavaScript and TypeScript Application
https://help.veracode.com/r/compilation_jscript
Topic: Schedule a Consultation
https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ
If the information we’ve provided you has helped resolve your challenge (or answered your question), we would appreciate it if you could mark the response that was helpful with “Select as Best”. This will help other Community members who come across your question as a similar challenge they might be facing and your best answer will help them find the right solution as well.
Jason
Veracode Support Engineer