PT-2023-11623 · Unknown · Jerryscript

Juckchang

·

Published

2023-07-03

·

Updated

2023-07-10

·

CVE-2020-22597

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jerryscrip version 2.3.0
Description An issue in the Jerryscrip project allows a remote attacker to execute arbitrary code via the ecma builtin array prototype object slice parameter.
Recommendations For Jerryscrip version 2.3.0, consider restricting access to the ecma builtin array prototype object slice parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2020-22597

Affected Products

Jerryscript