GHSA-q8j6-pwqx-pm96

    Dashboard / Vulnerabilities / GHSA-q8j6-pwqx-pm96

    GHSA-q8j6-pwqx-pm96

    Published: 17 May 2021Last Modified: 8 Nov 2023

    Summary: Insecure template handling in Squirrelly

    Details: Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. Version 9.0.0 has a fix for this issue. For complete details refer to the referenced [GHSL-2021-023](https://securitylab.github.com/advisories/GHSL-2021-023-squirrelly/).

    Affected packages

    Package

    Name: squirrelly

    Purl: pkg:npm/squirrelly

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -9.0.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-q8j6-pwqx-pm96 | CVE-DB