PT-2022-18605 · Hermes · Hermes
CVE-2022-27810
·
Published
2022-10-06
·
Updated
2022-10-11
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Hermes versions prior to v0.12.0
Description
The issue allows an infinite recursion condition to be triggered in the error handler when Hermes executes specific maliciously formed JavaScript. This condition can only be triggered in dev-mode, when asserts are enabled.
Recommendations
For versions prior to v0.12.0, update to version v0.12.0 or later to resolve the issue. As a temporary workaround, consider disabling dev-mode until a patch is available. Restrict the execution of maliciously formed JavaScript to minimize the risk of exploitation.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes