Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Remediation
References
http://www.securityfocus.com/bid/101897
https://snyk.io/vuln/npm:ejs:20161128
Related Vulnerabilities
CVE-2016-6796 Vulnerability in maven package org.apache.tomcat:tomcat-jasper
CVE-2019-1003057 Vulnerability in maven package org.jenkins-ci.plugins:bitbucket-approve
CVE-2019-19771 Vulnerability in npm package bs58chcek
CVE-2020-6452 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-48285 Vulnerability in maven package org.webjars.bowergithub.stuk:jszip