CVE-2021-32819: Nodejs Squirrelly – Remote Code Execution

CVE-2021-32819: Nodejs Squirrelly - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2021-32819: Nodejs Squirrelly – Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-32819: Nodejs Squirrelly – Remote Code Execution

漏洞描述

Nodejs Squirrelly is susceptible to remote code execution. Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. There is currently no fix for these issues as of the publication of this CVE. The latest version of squirrelly is currently 8.0.8. For complete details refer to the referenced GHSL-2021-023.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享