Vulnerabilities/

ejs lacks certain pollution protection

Severity:
Medium

Description

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

Recommendation

Update the ejs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ejs
Anything's wrong? Let us know Last updated on August 02, 2024

This issue is available in SmartScanner Professional

See Pricing