Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2018-11784 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-22580 Vulnerability in npm package @sequelize/core
CVE-2022-41828 Vulnerability in maven package com.amazon.redshift:redshift-jdbc42
CVE-2017-16135 Vulnerability in npm package serverzyy
CVE-2019-10742 Vulnerability in maven package org.webjars.bowergithub.axios:axios