Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45311

Опубликовано: 06 окт. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fsevents_project:fsevents:*:*:*:*:*:node.js:*:*
Версия до 1.2.11 (исключая)

EPSS

Процентиль: 62%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

CVSS3: 9.8
github
больше 2 лет назад

Code injection in fsevents

EPSS

Процентиль: 62%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94