Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mhc-prgv-r3q4

Опубликовано: 16 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Access of Resource Using Incompatible Type in Hermes

By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.

Пакеты

Наименование

hermes-engine

npm
Затронутые версииВерсия исправления

<= 0.9.0

0.10.0

EPSS

Процентиль: 66%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.

EPSS

Процентиль: 66%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-843