Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2019-16775 Vulnerability in maven package org.webjars:npm
CVE-2018-12585 Vulnerability in maven package org.opcfoundation.ua:opc-ua-stack
CVE-2016-0779 Vulnerability in maven package org.apache.tomee:arquillian-tomee-common
CVE-2018-20676 Vulnerability in maven package org.webjars.npm:bootstrap