Bug 2168980 (CVE-2022-25967)
| Summary: | CVE-2022-25967 eta: Remote Code Execution by overwriting template engine configuration variables | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Zack Miele <zmiele> |
| Component: | vulnerability | Assignee: | Nobody <nobody> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dshah, ellin, scorneli |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | eta 2.0.0 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found in the ETA npm package. Affected versions of this package are vulnerable to remote code execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2168981 | ||
| Bug Blocks: | 2165588 | ||
|
Description
Zack Miele
2023-02-10 21:03:17 UTC
Created golang-entgo-ent tracking bugs for this issue: Affects: fedora-36 [bug 2168981] |