Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2021-3645 Vulnerability in npm package @viking04/merge
CVE-2021-39133 Vulnerability in maven package org.rundeck:rundeck
CVE-2016-4465 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2023-30517 Vulnerability in maven package io.jenkins.plugins:neuvector-vulnerability-scanner
CVE-2022-31194 Vulnerability in maven package org.dspace:dspace-jspui