VDB
CVE-2023-29827
CVE-2023-29827
PUBLISHED
KEV
CVSS 9.300000190734863 CRITICAL
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.
EPSS 66.27% · 98.5th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
66.27%
98.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ejs | ejs | 3.1.9, 3.1.9 |
| n/a | n/a | n/a, n/a |
Exploit Intelligence
- (crowdsec)
- CIRCL seen: CVE-2023-29827 (circl-sighting)
- https://github.com/mde/ejs/issues/720 (nist-nvd)
- (crowdsec)
- (crowdsec)
- (crowdsec)
- https://github.com/mde/ejs/blob/main/SECURITY.md#out-of-scope-vulnerabilities (circl)
- (crowdsec)
- (crowdsec)
- (crowdsec)
…and 27 more exploits
Timeline
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Oct 21, 2021 CrowdSec Sighting
- Feb 22, 2023 CrowdSec Sighting
- Mar 26, 2023 CrowdSec Sighting
- May 4, 2023 CVE Published
- May 4, 2023 PoC Published
- May 5, 2023 EPSS Score
References
- https://github.com/mde/ejs/issues/720 url
- https://github.com/mde/ejs/blob/main/SECURITY.md#out-of-scope-vulnerabilities url
- https://nvd.nist.gov/vuln/detail/CVE-2023-29827 advisory
- https://www.ibm.com/support/pages/node/7148847 advisory
- https://www.ibm.com/support/pages/node/7149294 advisory
- https://www.ibm.com/support/pages/node/7149055 advisory
- https://www.ibm.com/support/pages/node/7149195 advisory