Record summary

CVE-2023-29827 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALEmbedded JavaScript(EJS) 3.1.6 - Template InjectionCVSS 9.8

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter.

Impact

High impact as it enables remote code execution.

Remediation

Update EJS to the latest version to mitigate the vulnerability.

WeaknessesCWE-74
Authorsritikchaddha
Template tagscvecve2023sstirceejsoastnode.jsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ejs:ejs:3.1.9:*:*:*:*:node.js:*:*

Source: ProjectDiscovery

References

3