Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-4947 (Critical) detected in rusty_v8-0.12.0.crate #61

Open
mend-bolt-for-github bot opened this issue Aug 11, 2024 · 0 comments
Open

CVE-2024-4947 (Critical) detected in rusty_v8-0.12.0.crate #61

mend-bolt-for-github bot opened this issue Aug 11, 2024 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Aug 11, 2024

CVE-2024-4947 - Critical Severity Vulnerability

Vulnerable Library - rusty_v8-0.12.0.crate

Rust bindings to V8

Library home page: https://crates.io/api/v1/crates/rusty_v8/0.12.0/download

Path to dependency file: /Cargo.toml

Path to vulnerable library: /Cargo.toml

Dependency Hierarchy:

  • test_plugin-0.0.1 (Root Library)
    • deno_core-0.65.0.crate
      • rusty_v8-0.12.0.crate (Vulnerable Library)

Found in HEAD commit: 6bd9a93e55faf7abd43040d83fa5bb6fcbd55f5c

Found in base branch: master

Vulnerability Details

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Publish Date: 2024-05-15

URL: CVE-2024-4947

CVSS 3 Score Details (9.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html

Release Date: 2024-05-15

Fix Resolution: b3c01ac1e60afc9addad9942f7a9a6c5e8a4a6da


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Aug 11, 2024
@mend-bolt-for-github mend-bolt-for-github bot changed the title CVE-2024-4947 (High) detected in rusty_v8-0.12.0.crate CVE-2024-4947 (Critical) detected in rusty_v8-0.12.0.crate Nov 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants