From 1632964eca11af4a3352887dbe7c32e4dc13e087 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 8 Sep 2023 20:55:37 +0000 Subject: [PATCH] Publish GHSA-3w5v-p54c-f74x --- .../11/GHSA-3w5v-p54c-f74x/GHSA-3w5v-p54c-f74x.json | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2017/11/GHSA-3w5v-p54c-f74x/GHSA-3w5v-p54c-f74x.json b/advisories/github-reviewed/2017/11/GHSA-3w5v-p54c-f74x/GHSA-3w5v-p54c-f74x.json index 10159a4d1cb..754c64cb04c 100644 --- a/advisories/github-reviewed/2017/11/GHSA-3w5v-p54c-f74x/GHSA-3w5v-p54c-f74x.json +++ b/advisories/github-reviewed/2017/11/GHSA-3w5v-p54c-f74x/GHSA-3w5v-p54c-f74x.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-3w5v-p54c-f74x", - "modified": "2022-06-29T00:53:15Z", + "modified": "2023-09-08T20:54:25Z", "published": "2017-11-30T23:15:19Z", "aliases": [ "CVE-2017-1000228" ], "summary": "ejs is vulnerable to remote code execution due to weak input validation", - "details": "nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function", + "details": "nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in `ejs.renderFile()` function", "severity": [ { "type": "CVSS_V3", @@ -20,6 +20,11 @@ "ecosystem": "npm", "name": "ejs" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "ranges": [ { "type": "ECOSYSTEM", @@ -53,7 +58,7 @@ }, { "type": "WEB", - "url": "http://www.securityfocus.com/bid/101897" + "url": "https://web.archive.org/web/20171123041219/http://www.securityfocus.com/bid/101897" } ], "database_specific": {