You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
mend-bolt-for-githubbot
changed the title
CVE-2024-4947 (High) detected in rusty_v8-0.12.0.crate
CVE-2024-4947 (Critical) detected in rusty_v8-0.12.0.crate
Nov 28, 2024
CVE-2024-4947 - Critical Severity Vulnerability
Vulnerable Library - rusty_v8-0.12.0.crate
Rust bindings to V8
Library home page: https://crates.io/api/v1/crates/rusty_v8/0.12.0/download
Path to dependency file: /Cargo.toml
Path to vulnerable library: /Cargo.toml
Dependency Hierarchy:
Found in HEAD commit: 6bd9a93e55faf7abd43040d83fa5bb6fcbd55f5c
Found in base branch: master
Vulnerability Details
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Publish Date: 2024-05-15
URL: CVE-2024-4947
CVSS 3 Score Details (9.6)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html
Release Date: 2024-05-15
Fix Resolution: b3c01ac1e60afc9addad9942f7a9a6c5e8a4a6da
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: