CVE Vulnerabilities

CVE-2024-33883

Protection Mechanism Failure

Published: Apr 28, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
Node-ejsUbuntuesm-apps/bionic*
Node-ejsUbuntuesm-apps/focal*
Node-ejsUbuntuesm-apps/jammy*
Node-ejsUbuntuesm-apps/noble*
Node-ejsUbuntufocal*
Node-ejsUbuntujammy*
Node-ejsUbuntumantic*
Node-ejsUbuntunoble*
Node-ejsUbuntuupstream*

References