Логотип exploitDog
bind:CVE-2024-45390
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45390

Количество 2

Количество 2

nvd логотип

CVE-2024-45390

больше 1 года назад

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-q765-wm9j-66qj

больше 1 года назад

@blakeembrey/template vulnerable to code injection when attacker controls template input

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45390

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-q765-wm9j-66qj

@blakeembrey/template vulnerable to code injection when attacker controls template input

CVSS3: 7.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу