S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-29078 Scanner

CVE-2022-29078 scanner - Server Side Template Injection (SSTI) vulnerability in ejs (aka Embedded JavaScript templates) package for Node.js

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-29078
9.8
CVSS

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The ejs (aka Embedded JavaScript templates) package is a popular Node.js view engine that allows developers to facilitate server-side template injection. This package can be used to create dynamic web pages, as it allows for the inclusion of data from a variety of sources, including databases, APIs, and local files. Ejs provides a simple syntax for creating templates with embedded JavaScript code, making it an efficient and flexible option for web developers.

Recently, a critical vulnerability, CVE-2022-29078, has been detected in ejs version 3.1.6. This vulnerability stems from a flaw in the parsing of internal options, which can be exploited to overwrite the outputFunctionName option with a malicious OS command. When ejs compiles a template with the user-supplied data, this command can be executed, potentially leading to a system compromise.

If this vulnerability is exploited, it can have devastating consequences. An attacker could gain complete control over the affected system, allowing them to execute arbitrary code, steal sensitive data, and launch further attacks on other systems. As ejs is a widely used package, this vulnerability has the potential to affect a large number of websites and applications.

With the pro features of the s4e.io platform, readers of this article can quickly and easily identify any vulnerabilities in their digital assets. This platform provides comprehensive scanning and reporting capabilities, utilizing machine learning and expert analysis to provide actionable insights into potential vulnerabilities. By using this platform, users can take proactive steps to secure their systems and prevent attacks before they occur.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users take the following precautions:

  • Update ejs package to the latest version (3.1.7 or later), where this vulnerability has been fixed.
  • Avoid using untrusted or user-supplied data in your templates.
  • Sanitize all input data to prevent any malicious input from being executed.
  • Implement strict input and output validation to prevent any malicious code from being executed.
  • Monitor your system for any unusual activity that may indicate an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.