**Note:** This is exploitable only for users who are rendering templates with user-defined data.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0508 | Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. |
Github GHSA |
GHSA-mf6x-hrgr-658f | Eta vulnerable to Code Injection via templates rendered with user-defined data |
Thu, 27 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-03-27T20:15:37.734Z
Reserved: 2022-02-24T11:58:25.179Z
Link: CVE-2022-25967
Updated: 2024-08-03T04:56:36.874Z
Status : Modified
Published: 2023-01-30T05:15:10.177
Modified: 2025-03-27T21:15:40.110
Link: CVE-2022-25967
OpenCVE Enrichment
No data.
EUVD
Github GHSA