QID 983782
QID 983782: Nodejs (npm) Security Update for ejs (GHSA-3w5v-p54c-f74x)
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3w5v-p54c-f74x for updates pertaining to this vulnerability.
Vendor References
- GHSA-3w5v-p54c-f74x -
github.com/advisories/GHSA-3w5v-p54c-f74x
CVEs related to QID 983782
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3w5v-p54c-f74x | ejs |
|