Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2020-7766 Vulnerability in maven package org.webjars.npm:json-ptr
CVE-2022-32533 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed
CVE-2023-40348 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2019-14820 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2017-3208 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer