@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2852 | @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature. |
Github GHSA |
GHSA-q765-wm9j-66qj | @blakeembrey/template vulnerable to code injection when attacker controls template input |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Sep 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blakeembrey template
|
|
| CPEs | cpe:2.3:a:blakeembrey:template:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Blakeembrey template
|
Tue, 03 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blakeembrey
Blakeembrey js-template |
|
| CPEs | cpe:2.3:a:blakeembrey:js-template:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Blakeembrey
Blakeembrey js-template |
|
| Metrics |
ssvc
|
Tue, 03 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature. | |
| Title | @blakeembrey/template vulnerable to code injection when attacker controls template input | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T20:01:40.797Z
Reserved: 2024-08-28T20:21:32.801Z
Link: CVE-2024-45390
Updated: 2024-09-03T20:01:36.837Z
Status : Analyzed
Published: 2024-09-03T20:15:08.423
Modified: 2024-09-12T20:15:15.673
Link: CVE-2024-45390
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA