CVE-2023-45311
Summary
| CVE | CVE-2023-45311 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-06 21:15:00 UTC |
| Updated | 2023-10-16 18:13:00 UTC |
| Description | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Comparing v1.2.10...v1.2.11 · fsevents/fsevents · GitHub |
MISC |
github.com |
|
| github.com/atlassian/react-immutable-proptypes/blob/ddb9fa5194b931bf7528... |
MISC |
github.com |
|
| github.com/cloudflare/serverless-cloudflare-workers/blob/e95e1e9c9770ed9... |
MISC |
github.com |
|
| github.com/cloudflare/authr/blob/3f6129d97d06e61033a7f237d84e35e678db490... |
MISC |
github.com |
|
| github.com/cloudflare/hugo-cloudflare-docs/blob/e0f7cfa195af8ef1bfa51a48... |
MISC |
github.com |
|
| github.com/cloudflare/redux-grim/blob/b652f99f95fb16812336073951adc5c5a9... |
MISC |
github.com |
|
| github.com/atlassian/moo/blob/56ccbdd41b493332bc2cd7a4097a5802594cdb9c/p... |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995554 NodeJs (Npm) Security Update for fsevents (GHSA-8r6j-v8pm-fqw3)