Lucene search

K
osvGoogleOSV:GHSA-X2JX-W3WM-9P3P
HistoryDec 05, 2022 - 6:30 a.m.

nadesiko3 allows remote attacker to inject invalid value to decodeURIComponent of nako3edit

2022-12-0506:30:22
Google
osv.dev
8
nadeshiko 3
nako3edit
remote attacker
code injection
vulnerability
decodeuricomponent.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

78.9%

Nako3edit is the editor component of Nadeshiko 3, a programming language developed based on Japanese. Improper check or handling of exceptional conditions in Nako3edit v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

78.9%

Related for OSV:GHSA-X2JX-W3WM-9P3P