Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11991

Опубликовано: 09 дек. 2024
Источник: nvd
CVSS3: 5.6
CVSS3: 6.5
EPSS Низкий

Описание

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this bug requires the Canister to enable the incremental garbage collector or enhanced orthogonal persistence, which are non-default features in Motoko.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dfinity:motoko:*:*:*:*:*:*:*:*
Версия от 0.9.0 (включая) до 0.13.4 (исключая)

EPSS

Процентиль: 19%
0.00058
Низкий

5.6 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-908

EPSS

Процентиль: 19%
0.00058
Низкий

5.6 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-908