Junglewise Threat Intelligence

CVE-2017-1000189: ejs denial of service via weak input validation

CVE-2017-1000189 · Severity: low · CVSS 3 · Published 2018-03-05

Technologies: Ejs. Vendors: npm.

Executive brief

ejs is a popular Node.js templating engine used to generate dynamic content in web applications. A vulnerability in versions before 2.5.5 allows an attacker to crash the application by sending specially crafted input to the renderFile() function, resulting in service outage without requiring authentication.

Technical details

The vulnerability is a denial-of-service (CWE-20: improper input validation) in ejs.renderFile() caused by insufficient validation of user-supplied input. The renderFile() function accepts options parameters that were not properly sanitized, allowing an attacker to pass unsafe options through the data object. No authentication is required and the vulnerability is network-accessible. An attacker can exploit this to trigger an unhandled exception or resource exhaustion, crashing the application and disrupting service availability. The fix was released in version 2.5.5, which implements a blacklist of unsafe options to prevent them from being passed via the data object.

Affected products

  • ejs ejs < 2.5.5

Timeline

  • 2018-03-05: disclosed

References

Related threats