PT-2022-23134 · Unknown · Circuitverse

P-Analyst

+1

·

Published

2022-09-06

·

Updated

2022-09-09

·

CVE-2022-36038

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CircuitVerse versions prior to the version with commit number 7b3023a99499a7675f10f2c1d9effdf10c35fb6e
Description CircuitVerse is an open-source platform for constructing digital logic circuits online. A remote code execution issue allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads, potentially leading to remote code execution.
Recommendations For versions prior to the version with commit number 7b3023a99499a7675f10f2c1d9effdf10c35fb6e, apply the patch available in commit number 7b3023a99499a7675f10f2c1d9effdf10c35fb6e to resolve the issue.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-36038
GHSA-8C8Q-4H7G-4RP3

Affected Products

Circuitverse