Lucene search

K
redhatcveRedhat.comRH:CVE-2023-37450
HistoryJul 19, 2023 - 4:06 p.m.

CVE-2023-37450

2023-07-1916:06:56
redhat.com
access.redhat.com
32
vulnerability
webkitgtk
arbitrary code execution
web content processing
mitigation
webassembly support

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

56.6%

A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code execution.

Mitigation

This vulnerability can be mitigated by setting the environment variable JSC_useWebAssembly=0, which will disable support for WebAssembly. It's not necessary to set this environment variable if you're already using JavaScriptCoreUseJIT=0 to mitigate other CVEs because WebAssembly depends on JIT.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

56.6%