Skip to content

[VULN] Security Alert for ejs #52

Description

@srm-feature3-dev-test

Alert IDs:

  • 2f2eebd0-2db1-4b28-ba1f-44d48d9e8399

Vulnerabilities in ejs

Release: New release

Total Vulnerabilities: 1


1. CVE-2023-29827

Severity: CRITICAL (Score: 9.8)

Description:
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.

Reference:https://nvd.nist.gov/vuln/detail/CVE-2023-29827

Alert ID: 2f2eebd0-2db1-4b28-ba1f-44d48d9e8399


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions