Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8j6-pwqx-pm96

Опубликовано: 17 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Insecure template handling in Squirrelly

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. Version 9.0.0 has a fix for this issue. For complete details refer to the referenced GHSL-2021-023.

Пакеты

Наименование

squirrelly

npm
Затронутые версииВерсия исправления

<= 8.0.8

9.0.0

EPSS

Процентиль: 99%
0.88448
Высокий

8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8
nvd
больше 4 лет назад

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

EPSS

Процентиль: 99%
0.88448
Высокий

8 High

CVSS3

Дефекты

CWE-200