Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25967

Опубликовано: 30 янв. 2023
Источник: nvd
CVSS3: 8.1
CVSS3: 8.8
EPSS Низкий

Описание

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API.

Note: This is exploitable only for users who are rendering templates with user-defined data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eta.js:eta:*:*:*:*:*:node.js:*:*
Версия до 2.0.0 (исключая)

EPSS

Процентиль: 87%
0.03526
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94
NVD-CWE-noinfo
CWE-94

Связанные уязвимости

CVSS3: 8.8
redhat
около 3 лет назад

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
github
около 3 лет назад

Eta vulnerable to Code Injection via templates rendered with user-defined data

EPSS

Процентиль: 87%
0.03526
Низкий

8.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-94
NVD-CWE-noinfo
CWE-94