Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23556

Опубликовано: 18 мая 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:*
Версия до 2023-02-02 (исключая)

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

EPSS

Процентиль: 61%
0.00408
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787