Eta vulnerable to Code Injection via templates rendered with user-defined data
High severity
GitHub Reviewed
Published
Jan 30, 2023
to the GitHub Advisory Database
•
Updated Feb 7, 2023
Description
Published by the National Vulnerability Database
Jan 30, 2023
Published to the GitHub Advisory Database
Jan 30, 2023
Reviewed
Feb 1, 2023
Last updated
Feb 7, 2023
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. Note: This is exploitable only for users who are rendering templates with user-defined data.
References