CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eta.js:eta:*:*:*:*:*:node.js:*:*

History

07 Nov 2023, 03:44

Type Values Removed Values Added
Summary Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

Information

Published : 2023-01-30 05:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-25967

Mitre link : CVE-2022-25967

CVE.ORG link : CVE-2022-25967


JSON object : View

Products Affected

eta.js

  • eta
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')