HIGH7.5
GHSA-6x77-rpqf-j6mw
ejs vulnerable to DoS due to weak input validation
Quick fix
GHSA-6x77-rpqf-j6mw — ejs: upgrade to the fixed version with the command below.
npm install ejs@2.5.5Details
nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in `ejs.renderFile()`
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000189[ADVISORY]
- https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f[WEB]
- https://github.com/advisories/GHSA-6x77-rpqf-j6mw[ADVISORY]
- https://github.com/mde/ejs[PACKAGE]
- https://web.archive.org/web/20171123041449/http://www.securityfocus.com/bid/101893[WEB]