Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2022-25898 Vulnerability in maven package org.webjars.npm:jsrsasign
CVE-2023-47326 Vulnerability in maven package org.silverpeas.core:silverpeas-core
CVE-2021-27884 Vulnerability in npm package yapi-vendor
CVE-2018-5673 Vulnerability in maven package org.dojotoolkit:dojo
CVE-2014-3490 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxb-provider