Server side template injection In eta
Description
Eta vulnerable to Code Injection via templates rendered with user-defined data Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. Note: This is exploitable only for users who are rendering templates with user-defined data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 2.0.0 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.