Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2023-49210 Vulnerability in npm package openssl
CVE-2021-25646 Vulnerability in maven package org.apache.druid:druid-core
CVE-2019-17573 Vulnerability in maven package org.apache.cxf:cxf-bundle
CVE-2021-25916 Vulnerability in npm package patchmerge
CVE-2020-10244 Vulnerability in maven package dev.paseto:jpaseto-impl