CVE-2023-45811

Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in `deobfuscator@2.4.4`. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags
Configurations

Configuration 1 (hide)

cpe:2.3:a:relative:synchrony:*:*:*:*:*:nodejs:*:*

History

25 Oct 2023, 13:33

Type Values Removed Values Added
CPE cpe:2.3:a:relative:synchrony:*:*:*:*:*:nodejs:*:*
First Time Relative
Relative synchrony
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-1321
References (MISC) https://github.com/relative/synchrony/security/advisories/src/transformers/literalmap.ts - (MISC) https://github.com/relative/synchrony/security/advisories/src/transformers/literalmap.ts - Broken Link
References (MISC) https://github.com/relative/synchrony/commit/b583126be94c4db7c5a478f1c5204bfb4162cf40 - (MISC) https://github.com/relative/synchrony/commit/b583126be94c4db7c5a478f1c5204bfb4162cf40 - Patch
References (MISC) https://github.com/relative/synchrony/security/advisories/GHSA-jg82-xh3w-rhxx - (MISC) https://github.com/relative/synchrony/security/advisories/GHSA-jg82-xh3w-rhxx - Exploit, Vendor Advisory

17 Oct 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-17 23:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-45811

Mitre link : CVE-2023-45811

CVE.ORG link : CVE-2023-45811


JSON object : View

Products Affected

relative

  • synchrony
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')