Lucene search

K
githubGitHub Advisory DatabaseGHSA-G7RJ-Q722-245G
HistoryMay 08, 2023 - 6:30 p.m.

jsreport vulnerable to code injection

2023-05-0818:30:17
CWE-94
GitHub Advisory Database
github.com
21
jsreport
code injection
vulnerability
cve-2023-29017
package.json
vm2
jsreport-core
attack
software

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.017

Percentile

88.0%

jsreport prior to 3.11.3 had a version of vm2 vulnerable to CVE-2023-29017 hard coded in the package.json of the jsreport-core component. An attacker can use this vulnerability to obtain the authority of the jsreport playground server, or construct a malicious webpage/html file and send it to the user to attack the installed jsreport client.

Affected configurations

Vulners
Node
jsreportRange<3.11.3

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.017

Percentile

88.0%