Описание
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
Ссылки
- PatchThird Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.4.3 (включая)
cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.002
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-195
CWE-681
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
Signed to Unsigned Conversion Error in Facebook Hermes
EPSS
Процентиль: 42%
0.002
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-195
CWE-681