Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2018-19057 Vulnerability in maven package org.webjars.npm:simplemde
CVE-2019-1003024 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2018-21234 Vulnerability in maven package org.jodd:jodd-json
CVE-2020-36144 Vulnerability in npm package redash
CVE-2023-51079 Vulnerability in maven package org.mvel:mvel2