PT-2023-22710 · Hermes · Hermes
CVE-2023-30470
·
Publicado
2023-05-18
·
Atualizado
2025-01-21
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hermes versions prior to commit da8990f737ebb9d9810633502f65ed462b819c09
Description
A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled could have been used by an attacker to achieve remote code execution. This issue is only exploitable in cases where Hermes is used to execute untrusted JavaScript, and most React Native applications are not affected.
Recommendations
For versions prior to commit da8990f737ebb9d9810633502f65ed462b819c09, update to a version that includes the fix for the use-after-free issue in bytecode generation. As a temporary workaround, consider disabling optimizations for Hermes when executing untrusted JavaScript until a patch is available.
Exploit
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hermes