Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2020-8203 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2018-17785 Vulnerability in maven package cc.blynk.server.api.core:http-core
CVE-2017-16052 Vulnerability in npm package node-fabric
CVE-2023-37957 Vulnerability in maven package io.jenkins.plugins:pipeline-restful-api