Bug 2150086 (CVE-2021-21353) - CVE-2021-21353 pug: user provided objects as input to pug templates can achieve remote code execution
Summary: CVE-2021-21353 pug: user provided objects as input to pug templates can achie...
Keywords:
Status: NEW
Alias: CVE-2021-21353
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2150073
TreeView+ depends on / blocked
 
Reported: 2022-12-01 19:56 UTC by Anten Skrabec
Modified: 2023-07-07 08:28 UTC (History)
2 users (show)

Fixed In Version: pug 3.0.1
Doc Type: ---
Doc Text:
A vulnerability was found in pug where a malicious user with access to the `pretty` option of the pug template compiler could achieve remote code execution on the backend through a user provided object.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Anten Skrabec 2022-12-01 19:56:14 UTC
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. This is fixed in version 3.0.1. This advisory applies to multiple pug packages including "pug", "pug-code-gen". pug-code-gen has a backported fix at version 2.0.3. This advisory is not exploitable if there is no way for un-trusted input to be passed to pug as the `pretty` option, e.g. if you compile templates in advance before applying user input to them, you do not need to upgrade.

https://github.com/pugjs/pug/commit/991e78f7c4220b2f8da042877c6f0ef5a4683be0
https://github.com/pugjs/pug/issues/3312
https://github.com/pugjs/pug/pull/3314
https://github.com/pugjs/pug/releases/tag/pug%403.0.1
https://github.com/pugjs/pug/security/advisories/GHSA-p493-635q-r6gr
https://www.npmjs.com/package/pug
https://www.npmjs.com/package/pug-code-gen


Note You need to log in before you can comment on or make changes to this bug.