First published: Mon Jan 30 2023(Updated: )
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Math.js | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25967 has a high severity rating due to the potential for remote code execution.
CVE-2022-25967 affects versions of the eta package prior to 2.0.0.
To fix CVE-2022-25967, update the eta package to version 2.0.0 or later.
CVE-2022-25967 allows for remote code execution through the manipulation of template engine configuration variables.
Users who render templates with user-defined data are vulnerable to CVE-2022-25967.