PT-2022-18605 · Hermes · Hermes
Published
2022-10-06
·
Updated
2022-10-11
·
CVE-2022-27810
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Hermes versions prior to v0.12.0
Description
The issue allows an infinite recursion condition to be triggered in the error handler when Hermes executes specific maliciously formed JavaScript. This condition can only be triggered in dev-mode, when asserts are enabled.
Recommendations
For versions prior to v0.12.0, update to version v0.12.0 or later to resolve the issue. As a temporary workaround, consider disabling dev-mode until a patch is available. Restrict the execution of maliciously formed JavaScript to minimize the risk of exploitation.
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes