QID 983766
QID 983766: Nodejs (npm) Security Update for ejs (GHSA-hwcf-pp87-7x6p)
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hwcf-pp87-7x6p for updates pertaining to this vulnerability.
Vendor References
- GHSA-hwcf-pp87-7x6p -
github.com/advisories/GHSA-hwcf-pp87-7x6p
CVEs related to QID 983766
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hwcf-pp87-7x6p | ejs |
|