You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
CVE-2020-1913 - High Severity Vulnerability
Vulnerable Library - hermes-engine-0.4.3.tgz
A JavaScript engine optimized for running React Native on Android
Library home page: https://registry.npmjs.org/hermes-engine/-/hermes-engine-0.4.3.tgz
Path to dependency file: /package.json
Path to vulnerable library: /node_modules/hermes-engine/package.json
Dependency Hierarchy:
Found in HEAD commit: 5cced2048a0851a07f123e0a3fe19d43b8e10c94
Found in base branch: master
Vulnerability Details
An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
Publish Date: 2020-09-09
URL: CVE-2020-1913
CVSS 3 Score Details (8.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://github.com/facebook/hermes/releases/tag/v0.7.0
Release Date: 2020-09-15
Fix Resolution (hermes-engine): 0.7.0
Direct dependency fix Resolution (react-native): 0.64.0-rc.0
The text was updated successfully, but these errors were encountered: