Lucene search

K
cve[email protected]CVE-2024-23347
HistoryJan 16, 2024 - 6:15 p.m.

CVE-2024-23347

2024-01-1618:15:11
web.nvd.nist.gov
11
cve
nvd
security
vulnerability
meta spark studio
package.json

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.2%

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

Affected configurations

NVD
Node
facebookmeta_spark_studioRange<176

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Meta Spark Studio",
    "vendor": "Meta Platforms, Inc",
    "versions": [
      {
        "lessThan": "176",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

23.2%

Related for CVE-2024-23347