CVE-2022-29078

EUVD-2022-1801
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
ejsejs
3.1.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-ejs
bookworm
3.1.8+~3.1.1-2
fixed
bullseye
2.5.7-3+deb11u1
fixed
sid
3.1.10+~3.1.5-2
fixed
trixie
3.1.10+~3.1.5-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-ejs
bionic
needs-triage
focal
needs-triage
impish
ignored
jammy
needs-triage
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
dne