Описание
ejs is vulnerable to remote code execution due to weak input validation
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Пакеты
Наименование
ejs
npm
Затронутые версииВерсия исправления
< 2.5.3
2.5.5
Связанные уязвимости
CVSS3: 9.8
nvd
около 8 лет назад
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
CVSS3: 9.8
debian
около 8 лет назад
nodejs ejs versions older than 2.5.3 is vulnerable to remote code exec ...