Описание
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.12.0 (исключая)
cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00317
Низкий
7.5 High
CVSS3
Дефекты
CWE-674
CWE-674
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciously formed JavaScript. This condition was only possible to trigger in dev-mode (when asserts were enabled). This issue affects Hermes versions prior to v0.12.0.
EPSS
Процентиль: 54%
0.00317
Низкий
7.5 High
CVSS3
Дефекты
CWE-674
CWE-674