CVE Vulnerabilities

CVE-2024-33883

Protection Mechanism Failure

Published: Apr 28, 2024 | Modified: Aug 01, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

Name Vendor Start Version End Version
Node-ejs Ubuntu esm-apps/bionic *
Node-ejs Ubuntu esm-apps/focal *
Node-ejs Ubuntu esm-apps/jammy *
Node-ejs Ubuntu esm-apps/noble *
Node-ejs Ubuntu focal *
Node-ejs Ubuntu jammy *
Node-ejs Ubuntu mantic *
Node-ejs Ubuntu noble *
Node-ejs Ubuntu upstream *

References