Bug#1010383: bullseye-pu: package node-ejs/2.5.7-3+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-04-30 at 09:11 +0200, Yadd wrote: > node-ejs is vulnerable to server-side template injection > (CVE-2022-29078, #1010359) and probably to prototype pollution. > Please go ahead. Regards, Adam

Bug#1010383: bullseye-pu: package node-ejs/2.5.7-3+deb11u1

2022-04-30 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-ejs is vulnerable to server-side template injection (CVE-2022-29078, #1010359) and probably to prototype pollution. [ Impact ] Medium security issue [ Tests ]