Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25967

Опубликовано: 30 янв. 2023
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. Note: This is exploitable only for users who are rendering templates with user-defined data.

A flaw was found in the ETA npm package. Affected versions of this package are vulnerable to remote code execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2168980eta: Remote Code Execution by overwriting template engine configuration variables

EPSS

Процентиль: 87%
0.03526
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 3 лет назад

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
github
около 3 лет назад

Eta vulnerable to Code Injection via templates rendered with user-defined data

EPSS

Процентиль: 87%
0.03526
Низкий

8.8 High

CVSS3