CVE-2023-45811
Summary
| CVE | CVE-2023-45811 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-17 23:15:00 UTC |
| Updated | 2023-10-25 13:33:00 UTC |
| Description | Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in `[email protected]`. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags |
Risk And Classification
Problem Types: CWE-1321
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/relative/synchrony/security/advisories/src/transformers/liter... | MISC | github.com | |
| Prototype pollution vulnerability leading to arbitrary code execution · Advisory · relative/synchrony · GitHub | MISC | github.com | |
| Merge pull request from GHSA-jg82-xh3w-rhxx · relative/synchrony@b583126 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995641 NodeJs (Npm) Security Update for deobfuscator (GHSA-jg82-xh3w-rhxx)