Skip to content

CVE-2024-3159 (High) detected in nodev15.3.0Β #631

@mend-bolt-for-github

Description

@mend-bolt-for-github

CVE-2024-3159 - High Severity Vulnerability

Vulnerable Library - nodev15.3.0

Node.js JavaScript runtime βœ¨πŸ’πŸš€βœ¨

Library home page: https://github.com/nodejs/node.git

Found in HEAD commit: 034a6d9c041d2f56d0c835c69088ea8b954f0b5f

Found in base branch: master

Vulnerable Source Files (1)

/deps/v8/src/objects/map-updater.cc

Vulnerability Details

Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Publish Date: 2024-04-06

URL: CVE-2024-3159

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://security-tracker.debian.org/tracker/CVE-2024-3159

Release Date: 2024-04-06

Fix Resolution: 807cf7d0b7d96212c98ed2119e07f9b2c6a23f61


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions