Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40747
HistoryMay 31, 2023 - 9:10 a.m.

Type Confusion

2023-05-3109:10:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
hermes-engine
type confusion
javascript
injection
malicious code
object properties

7.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.2%

hermes-engine is vulnerable to Type Confusion. When Hermes allows execution of untrusted JavaScript, an attacker is able to inject and execute malicious code on the system due to a type confusion bug which occurs as a result of copying objects properties.

7.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.2%

Related for VERACODE:40747