Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2020-28501 Vulnerability in npm package es6-crawler-detect
CVE-2023-26143 Vulnerability in npm package blamer
CVE-2015-2080 Vulnerability in maven package org.eclipse.jetty.aggregate:jetty-all
CVE-2023-31716 Vulnerability in npm package @frangoteam/fuxa
CVE-2016-0762 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core