Red Hat Bugzilla – Bug 1404187
CVE-2017-1000188 nodejs-ejs: Cross-site scripting via ejs.renderFile()
Last modified: 2018-01-29 22:14:40 EST
A cross-site scripting vulnerability was found in nodejs-ejs < 2.5.5 that allows the attacker under certain conditions control and override the filename option causing it to render the value as is, without escaping it. Upstream patch: https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f External Reference: https://snyk.io/vuln/npm:ejs:20161130
Created nodejs-ejs tracking bugs for this issue: Affects: fedora-all [bug 1404189] Affects: epel-all [bug 1404190]