Логотип exploitDog
bind:CVE-2022-25967
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25967

Количество 3

Количество 3

redhat логотип

CVE-2022-25967

около 3 лет назад

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-25967

около 3 лет назад

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-mf6x-hrgr-658f

около 3 лет назад

Eta vulnerable to Code Injection via templates rendered with user-defined data

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
4%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.1
4%
Низкий
около 3 лет назад
github логотип
GHSA-mf6x-hrgr-658f

Eta vulnerable to Code Injection via templates rendered with user-defined data

CVSS3: 8.8
4%
Низкий
около 3 лет назад

Уязвимостей на страницу