Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2019-10767 Vulnerability in npm package iobroker.js-controller
CVE-2021-39177 Vulnerability in maven package org.geysermc:connector
CVE-2019-10769 Vulnerability in maven package org.webjars.npm:safer-eval
CVE-2020-13961 Vulnerability in npm package strapi
CVE-2019-1003042 Vulnerability in maven package org.6wind.jenkins:lockable-resources