@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Blakeembrey template
|
|
CPEs | cpe:2.3:a:blakeembrey:template:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Blakeembrey template
|
Tue, 03 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Blakeembrey
Blakeembrey js-template |
|
CPEs | cpe:2.3:a:blakeembrey:js-template:*:*:*:*:*:*:*:* | |
Vendors & Products |
Blakeembrey
Blakeembrey js-template |
|
Metrics |
ssvc
|
Tue, 03 Sep 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature. | |
Title | @blakeembrey/template vulnerable to code injection when attacker controls template input | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-03T19:37:31.763Z
Updated: 2024-09-03T20:01:40.797Z
Reserved: 2024-08-28T20:21:32.801Z
Link: CVE-2024-45390
Vulnrichment
Updated: 2024-09-03T20:01:36.837Z
NVD
Status : Analyzed
Published: 2024-09-03T20:15:08.423
Modified: 2024-09-12T20:15:15.673
Link: CVE-2024-45390
Redhat
No data.