Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r83x-wj75-v89r

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Nuclide Improper Input Validation

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.

Пакеты

Наименование

nuclide

npm
Затронутые версииВерсия исправления

< 0.290.0

0.290.0

EPSS

Процентиль: 78%
0.01115
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.

EPSS

Процентиль: 78%
0.01115
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-79