Количество 3
Количество 3
CVE-2022-25967
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
CVE-2022-25967
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
GHSA-mf6x-hrgr-658f
Eta vulnerable to Code Injection via templates rendered with user-defined data
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-25967 Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. | CVSS3: 8.8 | 4% Низкий | около 3 лет назад | |
CVE-2022-25967 Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. | CVSS3: 8.1 | 4% Низкий | около 3 лет назад | |
GHSA-mf6x-hrgr-658f Eta vulnerable to Code Injection via templates rendered with user-defined data | CVSS3: 8.8 | 4% Низкий | около 3 лет назад |
Уязвимостей на страницу