CVE-2023-5654
Summary
| CVE | CVE-2023-5654 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-19 15:15:00 UTC |
| Updated | 2023-10-27 21:53:00 UTC |
| Description | The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | React-devtools | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| React Developer Tools v4.27.8 Arbitrary URL Fetch via Malicious Web Page · GitHub | MISC | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995679 NodeJs (Npm) Security Update for react-devtools-core (GHSA-rxrc-rgv4-jpvx)