Description
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Recommendation
Update the ejs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.1.10
- Patched version(s): 3.1.10
References
Related Issues
- json-schema-ref-parser Prototype Pollution issue - CVE-2024-29651
- jsonic was discovered to contain a prototype pollution via the function empty. - CVE-2024-38993
- @thi.ng/paths Prototype Pollution vulnerability - CVE-2024-29650
- jrburke requirejs vulnerable to prototype pollution - CVE-2024-38999
- Tags:
- npm
- ejs
Anything's wrong? Let us know Last updated on August 02, 2024