PT-2024-23300 · Solana · @Solana/Web3.Js

Fixedlocally

·

Published

2024-04-17

·

Updated

2024-04-17

·

CVE-2024-30253

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions @solana/web3.js versions prior to 1.0.1 @solana/web3.js versions prior to 1.10.2 @solana/web3.js versions prior to 1.11.1 @solana/web3.js versions prior to 1.12.1 @solana/web3.js versions prior to 1.1.2 @solana/web3.js versions prior to 1.13.1 @solana/web3.js versions prior to 1.14.1 @solana/web3.js versions prior to 1.15.1 @solana/web3.js versions prior to 1.16.2 @solana/web3.js versions prior to 1.17.1 @solana/web3.js versions prior to 1.18.1 @solana/web3.js versions prior to 1.19.1 @solana/web3.js versions prior to 1.20.3 @solana/web3.js versions prior to 1.21.1 @solana/web3.js versions prior to 1.22.1 @solana/web3.js versions prior to 1.23.1 @solana/web3.js versions prior to 1.24.3 @solana/web3.js versions prior to 1.25.1 @solana/web3.js versions prior to 1.26.1 @solana/web3.js versions prior to 1.27.1 @solana/web3.js versions prior to 1.28.1 @solana/web3.js versions prior to 1.2.8 @solana/web3.js versions prior to 1.29.4 @solana/web3.js versions prior to 1.30.3 @solana/web3.js versions prior to 1.31.1 @solana/web3.js versions prior to 1.3.1 @solana/web3.js versions prior to 1.32.3 @solana/web3.js versions prior to 1.33.1 @solana/web3.js versions prior to 1.34.1 @solana/web3.js versions prior to 1.35.2 @solana/web3.js versions prior to 1.36.1 @solana/web3.js versions prior to 1.37.3 @solana/web3.js versions prior to 1.38.1 @solana/web3.js versions prior to 1.39.2 @solana/web3.js versions prior to 1.40.2 @solana/web3.js versions prior to 1.41.11 @solana/web3.js versions prior to 1.4.1 @solana/web3.js versions prior to 1.42.1 @solana/web3.js versions prior to 1.43.7 @solana/web3.js versions prior to 1.44.4 @solana/web3.js versions prior to 1.45.1 @solana/web3.js versions prior to 1.46.1 @solana/web3.js versions prior to 1.47.5 @solana/web3.js versions prior to 1.48.1 @solana/web3.js versions prior to 1.49.1 @solana/web3.js versions prior to 1.50.2 @solana/web3.js versions prior to 1.51.1 @solana/web3.js versions prior to 1.5.1 @solana/web3.js versions prior to 1.52.1 @solana/web3.js versions prior to 1.53.1 @solana/web3.js versions prior to 1.54.2 @solana/web3.js versions prior to 1.55.1 @solana/web3.js versions prior to 1.56.3 @solana/web3.js versions prior to 1.57.1 @solana/web3.js versions prior to 1.58.1 @solana/web3.js versions prior to 1.59.2 @solana/web3.js versions prior to 1.60.1 @solana/web3.js versions prior to 1.61.2 @solana/web3.js versions prior to 1.6.1 @solana/web3.js versions prior to 1.62.2 @solana/web3.js versions prior to 1.63.2 @solana/web3.js versions prior to 1.64.1 @solana/web3.js versions prior to 1.65.1 @solana/web3.js versions prior to 1.66.6 @solana/web3.js versions prior to 1.67.3 @solana/web3.js versions prior to 1.68.2 @solana/web3.js versions prior to 1.69.1 @solana/web3.js versions prior to 1.70.4 @solana/web3.js versions prior to 1.71.1 @solana/web3.js versions prior to 1.72.1 @solana/web3.js versions prior to 1.7.2 @solana/web3.js versions prior to 1.73.5 @solana/web3.js versions prior to 1.74.1 @solana/web3.js versions prior to 1.75.1 @solana/web3.js versions prior to 1.76.1 @solana/web3.js versions prior to 1.77.4 @solana/web3.js versions prior to 1.78.8 @solana/web3.js versions prior to 1.79.1 @solana/web3.js versions prior to 1.80.1 @solana/web3.js versions prior to 1.81.1 @solana/web3.js versions prior to 1.8.1 @solana/web3.js versions prior to 1.82.1 @solana/web3.js versions prior to 1.83.1 @solana/web3.js versions prior to 1.84.1 @solana/web3.js versions prior to 1.85.1 @solana/web3.js versions prior to 1.86.1 @solana/web3.js versions prior to 1.87.7 @solana/web3.js versions prior to 1.88.1 @solana/web3.js versions prior to 1.89.2 @solana/web3.js versions prior to 1.90.2 @solana/web3.js versions prior to 1.9.2 @solana/web3.js versions prior to 1.91.3
Description Using particular inputs with @solana/web3.js will result in memory exhaustion, potentially causing a server, client, mobile, or desktop product to crash and resulting in a loss of availability.
Recommendations Update to version 1.0.1 or later to resolve the issue. Update to version 1.10.2 or later to resolve the issue. Update to version 1.11.1 or later to resolve the issue. Update to version 1.12.1 or later to resolve the issue. Update to version 1.1.2 or later to resolve the issue. Update to version 1.13.1 or later to resolve the issue. Update to version 1.14.1 or later to resolve the issue. Update to version 1.15.1 or later to resolve the issue. Update to version 1.16.2 or later to resolve the issue. Update to version 1.17.1 or later to resolve the issue. Update to version 1.18.1 or later to resolve the issue. Update to version 1.19.1 or later to resolve the issue. Update to version 1.20.3 or later to resolve the issue. Update to version 1.21.1 or later to resolve the issue. Update to version 1.22.1 or later to resolve the issue. Update to version 1.23.1 or later to resolve the issue. Update to version 1.24.3 or later to resolve the issue. Update to version 1.25.1 or later to resolve the issue. Update to version 1.26.1 or later to resolve the issue. Update to version 1.27.1 or later to resolve the issue. Update to version 1.28.1 or later to resolve the issue. Update to version 1.2.8 or later to resolve the issue. Update to version 1.29.4 or later to resolve the issue. Update to version 1.30.3 or later to resolve the issue. Update to version 1.31.1 or later to resolve the issue. Update to version 1.3.1 or later to resolve the issue. Update to version 1.32.3 or later to resolve the issue. Update to version 1.33.1 or later to resolve the issue. Update to version 1.34.1 or later to resolve the issue. Update to version 1.35.2 or later to resolve the issue. Update to version 1.36.1 or later to resolve the issue. Update to version 1.37.3 or later to resolve the issue. Update to version 1.38.1 or later to resolve the issue. Update to version 1.39.2 or later to resolve the issue. Update to version 1.40.2 or later to resolve the issue. Update to version 1.41.11 or later to resolve the issue. Update to version 1.4.1 or later to resolve the issue. Update to version 1.42.1 or later to resolve the issue. Update to version 1.43.7 or later to resolve the issue. Update to version 1.44.4 or later to resolve the issue. Update to version 1.45.1 or later to resolve the issue. Update to version 1.46.1 or later to resolve the issue. Update to version 1.47.5 or later to resolve the issue. Update to version 1.48.1 or later to resolve the issue. Update to version 1.49.1 or later to resolve the issue. Update to version 1.50.2 or later to resolve the issue. Update to version 1.51.1 or later to resolve the issue. Update to version 1.5.1 or later to resolve the issue. Update to version 1.52.1 or later to resolve the issue. Update to version 1.53.1 or later to resolve the issue. Update to version 1.54.2 or later to resolve the issue. Update to version 1.55.1 or later to resolve the issue. Update to version 1.56.3 or later to resolve the issue. Update to version 1.57.1 or later to resolve the issue. Update to version 1.58.1 or later to resolve the issue. Update to version 1.59.2 or later to resolve the issue. Update to version 1.60.1 or later to resolve the issue. Update to version 1.61.2 or later to resolve the issue. Update to version 1.6.1 or later to resolve the issue. Update to version 1.62.2 or later to resolve the issue. Update to version 1.63.2 or later to resolve the issue. Update to version 1.64.1 or later to resolve the issue. Update to version 1.65.1 or later to resolve the issue. Update to version 1.66.6 or later to resolve the issue. Update to version 1.67.3 or later to resolve the issue. Update to version 1.68.2 or later to resolve the issue. Update to version 1.69.1 or later to resolve the issue. Update to version 1.70.4 or later to resolve the issue. Update to version 1.71.1 or later to resolve the issue. Update to version 1.72.1 or later to resolve the issue. Update to version 1.7.2 or later to resolve the issue. Update to version 1.73.5 or later to resolve the issue. Update to version 1.74.1 or later to resolve the issue. Update to version 1.75.1 or later to resolve the issue. Update to version 1.76.1 or later to resolve the issue. Update to version 1.77.4 or later to resolve the issue. Update to version 1.78.8 or later to resolve the issue. Update to version 1.79.1 or later to resolve the issue. Update to version 1.80.1 or later to resolve the issue. Update to version 1.81.1 or later to resolve the issue. Update to version 1.8.1 or later to resolve the issue. Update to version 1.82.1 or later to resolve the issue. Update to version 1.83.1 or later to resolve the issue. Update to version 1.84.1 or later to resolve the issue. Update to version 1.85.1 or later to resolve the issue. Update to version 1.86.1 or later to resolve the issue. Update to version 1.87.7 or later to resolve the issue. Update to version 1.88.1 or later to resolve the issue. Update to version 1.89.2 or later to resolve the issue. Update to version 1.90.2 or later to resolve the issue. Update to version 1.9.2 or later to resolve the issue. Update to version 1.91.3 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-30253
GHSA-8M45-2RJM-J347

Affected Products

@Solana/Web3.Js