Логотип exploitDog
bind:CVE-2024-45489
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45489

Количество 3

Количество 3

nvd логотип

CVE-2024-45489

больше 1 года назад

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-84q8-hphj-4r7w

больше 1 года назад

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however, it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-08200

больше 1 года назад

Уязвимость функции Boosts браузера Arc, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45489

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

CVSS3: 9.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-84q8-hphj-4r7w

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however, it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context.

CVSS3: 9.8
3%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-08200

Уязвимость функции Boosts браузера Arc, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 9.8
3%
Низкий
больше 1 года назад

Уязвимостей на страницу