Lucene search

K
cve[email protected]CVE-2023-23556
HistoryMay 18, 2023 - 10:15 p.m.

CVE-2023-23556

2023-05-1822:15:09
CWE-787
web.nvd.nist.gov
10
cve-2023-23556
bigint
number
hermes
arbitrary code
out-of-bound write
javascript
react native
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.2%

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.

Affected configurations

NVD
Node
facebookhermesRange<2023-02-02

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Hermes",
    "vendor": "Facebook",
    "versions": [
      {
        "lessThan": "a6dcafe6ded8e61658b40f5699878cd19a481f80",
        "status": "affected",
        "version": "0",
        "versionType": "git"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.2%