Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2023-1108 Vulnerability in maven package io.undertow:undertow-core
CVE-2017-5664 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2013-4590 Vulnerability in maven package org.apache.tomcat:catalina-ant
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap