Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2gp-86p4-5935

Опубликовано: 02 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Use-After-Free in puppeteer

Versions of puppeteer prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.

Recommendation

Upgrade to version 1.13.0 or later.

Пакеты

Наименование

puppeteer

npm
Затронутые версииВерсия исправления

< 1.13.0

1.13.0

EPSS

Процентиль: 100%
0.8945
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 8.8
redhat
почти 7 лет назад

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
nvd
больше 6 лет назад

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 6.5
debian
больше 6 лет назад

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 ...

suse-cvrf
почти 7 лет назад

Security update for chromium

EPSS

Процентиль: 100%
0.8945
Высокий

6.5 Medium

CVSS3

Дефекты

CWE-416