Lucene search

K
nvd[email protected]NVD:CVE-2023-45811
HistoryOct 17, 2023 - 11:15 p.m.

CVE-2023-45811

2023-10-1723:15:12
CWE-1321
web.nvd.nist.gov
3
synchrony deobfuscator
javascript cleaner
deobfuscator
__proto__ pollution
arbitrary code execution
literalmap transformer
object prototype
upgrade
node launch

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0

Percentile

9.8%

Synchrony deobfuscator is a javascript cleaner & deobfuscator. A __proto__ pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A __proto__ pollution vulnerability exists in the LiteralMap transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in [email protected]. Users are advised to upgrade. Users unable to upgrade should launch node with the [–disable-proto=delete][disable-proto] or [–disable-proto=throw][disable-proto] flags

Affected configurations

Nvd
Node
relativesynchronyRange2.0.12.4.4nodejs
VendorProductVersionCPE
relativesynchrony*cpe:2.3:a:relative:synchrony:*:*:*:*:*:nodejs:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0

Percentile

9.8%