CRITICAL9.8
GHSA-phwq-j96m-2c2q
ejs template injection vulnerability
Quick fix
GHSA-phwq-j96m-2c2q — ejs: upgrade to the fixed version with the command below.
npm install ejs@3.1.7Details
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-29078[ADVISORY]
- https://github.com/mde/ejs/commit/15ee698583c98dadc456639d6245580d17a24baf[WEB]
- https://eslam.io/posts/ejs-server-side-template-injection-rce[WEB]
- https://github.com/mde/ejs[PACKAGE]
- https://github.com/mde/ejs/releases[WEB]
- https://security.netapp.com/advisory/ntap-20220804-0001[WEB]