PT-2024-28852 · Unknown · Squirrelly

Owoverflow

·

Published

2024-08-21

·

Updated

2024-08-25

·

CVE-2024-40453

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions squirrellyjs squirrelly version 9.0.0
Description The issue is a code injection vulnerability via the component options.varName. This vulnerability was discovered in squirrellyjs squirrelly and was fixed in version 9.0.1, however, another source indicates it was fixed in version 9.1.0.
Recommendations For version 9.0.0, update to version 9.0.1 or 9.1.0 to resolve the issue. As a temporary workaround, consider restricting the use of the options.varName component until a patch is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-40453
GHSA-W5PW-GMCW-RFC8

Affected Products

Squirrelly