Node.js ejs Package 'ejs.renderFile()' Function Remote Code Execution Vulnerability
BID:101897
Info
Node.js ejs Package 'ejs.renderFile()' Function Remote Code Execution Vulnerability
| Bugtraq ID: | 101897 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-1000228 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2017 12:00AM |
| Updated: | Dec 19 2017 10:00PM |
| Credit: | Snyk Security Research Team |
| Vulnerable: |
mde ejs 2.5.2 mde ejs 2.5.1 mde ejs 2.4.2 mde ejs 2.4.1 mde ejs 2.3.4 |
| Not Vulnerable: |
mde ejs 2.5.3 |
Discussion
Node.js ejs Package 'ejs.renderFile()' Function Remote Code Execution Vulnerability
The ejs Package for Node.js is prone to remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
Versions prior to ejs 2.5.3 are vulnerable.
The ejs Package for Node.js is prone to remote code-execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application. Failed exploits will result in denial-of-service conditions.
Versions prior to ejs 2.5.3 are vulnerable.
Exploit / POC
Node.js ejs Package 'ejs.renderFile()' Function Remote Code Execution Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Node.js ejs Package 'ejs.renderFile()' Function Remote Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].