Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
https://snyk.io/vuln/npm:ejs:20161128
http://www.securityfocus.com/bid/101897
Related Vulnerabilities
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint
CVE-2020-26274 Vulnerability in npm package systeminformation
CVE-2021-25949 Vulnerability in npm package set-getter
CVE-2021-39151 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-10991 Vulnerability in maven package org.mule.modules:mule-module-apikit