CVE-2024-33883
Severity CVSS v4.0:
Pending analysis
Type:
CWE-693
Protection Mechanism Failure
Publication date:
28/04/2024
Last modified:
15/04/2026
Description
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Impact
Base Score 3.x
4.00
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/mde/ejs/commit/e469741dca7df2eb400199e1cdb74621e3f89aa5
- https://github.com/mde/ejs/compare/v3.1.9...v3.1.10
- https://security.netapp.com/advisory/ntap-20240605-0003/
- https://github.com/mde/ejs/commit/e469741dca7df2eb400199e1cdb74621e3f89aa5
- https://github.com/mde/ejs/compare/v3.1.9...v3.1.10
- https://security.netapp.com/advisory/ntap-20240605-0003/



