漏洞描述
Node.js Embedded JavaScript 3.1.6 is susceptible to server-side template injection via settings[view options][outputFunctionName], which is parsed as an internal option and overwrites the outputFunctionName option with an arbitrary OS command, which is then executed upon template compilation.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
eslam.iohttps://eslam.io/posts/ejs-server-side-template-injection-rce/↗github.comhttps://github.com/miko550/CVE-2022-29078↗github.comhttps://github.com/mde/ejs/commit/15ee698583c98dadc456639d6245580d17a24baf↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-29078↗github.comhttps://github.com/mde/ejs/releases↗