mde / ejs

Embedded JavaScript templates -- http://ejs.co
Apache License 2.0
7.79k stars 843 forks source link

ejs:3.1.10 Vulnerability #770

Closed AES-SL closed 2 months ago

AES-SL commented 2 months ago

Hello I meet a problem with this librairie

the tool Dependency-Check of OWAST tel me there is a Vulnerability with this lib ejs:

Filename: ejs:3.1.10 | Highest CVSS Score: 9.8 | Amount of CVSS: 1 | References: CVE-2023-29827 (9.8)

RyanZim commented 2 months ago

Duplicate of https://github.com/mde/ejs/issues/720.

AES-SL commented 2 months ago

not exactly the same because the problem due to version 3.1.10 of ejs

RyanZim commented 2 months ago

The same information applies to this as well