The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Node-ejs | Ubuntu | esm-apps/bionic | * |
Node-ejs | Ubuntu | esm-apps/focal | * |
Node-ejs | Ubuntu | esm-apps/jammy | * |
Node-ejs | Ubuntu | esm-apps/noble | * |
Node-ejs | Ubuntu | focal | * |
Node-ejs | Ubuntu | jammy | * |
Node-ejs | Ubuntu | mantic | * |
Node-ejs | Ubuntu | noble | * |
Node-ejs | Ubuntu | upstream | * |