Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23347

Опубликовано: 16 янв. 2024
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:facebook:meta_spark_studio:*:*:*:*:*:*:*:*
Версия до 176 (исключая)

EPSS

Процентиль: 46%
0.00234
Низкий

7.8 High

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
github
около 2 лет назад

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

EPSS

Процентиль: 46%
0.00234
Низкий

7.8 High

CVSS3

Дефекты

NVD-CWE-noinfo