wagner-deoliveira / mobile-expo

0 stars 0 forks source link

CVE-2020-1915 (High) detected in hermes-engine-0.0.0.tgz #93

Open mend-bolt-for-github[bot] opened 1 year ago

mend-bolt-for-github[bot] commented 1 year ago

CVE-2020-1915 - High Severity Vulnerability

Vulnerable Library - hermes-engine-0.0.0.tgz

Library home page: https://registry.npmjs.org/hermes-engine/-/hermes-engine-0.0.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/hermes-engine/package.json

Dependency Hierarchy: - react-native-0.62.2.tgz (Root Library) - :x: **hermes-engine-0.0.0.tgz** (Vulnerable Library)

Found in HEAD commit: 2dadebde961db14e094d77b44fb513bffe8b7f6b

Found in base branch: master

Vulnerability Details

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

Publish Date: 2020-10-26

URL: CVE-2020-1915

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-x4cf-6jr3-3qvp

Release Date: 2020-11-02

Fix Resolution: hermes-engine - 0.7.2


Step up your Open Source Security Game with Mend here