MEDIUM6.1
GHSA-hwcf-pp87-7x6p
mde ejs vulnerable to XSS
Quick fix
GHSA-hwcf-pp87-7x6p — ejs: upgrade to the fixed version with the command below.
npm install ejs@2.5.5Details
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the `ejs.renderFile()` resulting in code injection
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000188[ADVISORY]
- https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f[WEB]
- https://github.com/advisories/GHSA-hwcf-pp87-7x6p[ADVISORY]
- https://github.com/mde/ejs[PACKAGE]
- https://web.archive.org/web/20200227134555/http://www.securityfocus.com/bid/101889[WEB]