Skip to content

CVE-2024-5158 (High) detected in io.jsv14.13.1Β #633

@mend-bolt-for-github

Description

@mend-bolt-for-github

CVE-2024-5158 - High Severity Vulnerability

Vulnerable Library - io.jsv14.13.1

Node.js JavaScript runtime βœ¨πŸ’πŸš€βœ¨

Library home page: https://github.com/iojs/io.js.git

Found in HEAD commit: 816eb239406f6f1ea0705d8f7029bf859bdd56ae

Found in base branch: master

Vulnerable Source Files (1)

/deps/v8/src/builtins/builtins-array.cc

Vulnerability Details

Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Publish Date: 2024-05-22

URL: CVE-2024-5158

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://issues.chromium.org/issues/338908243

Release Date: 2024-05-22

Fix Resolution: cc05792346fb017eaa961ee7d35cf1f9bb53bb0a


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions