CVE-2024-23347

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:facebook:meta_spark_studio:*:*:*:*:*:*:*:*

History

30 Jan 2024, 15:09

Type Values Removed Values Added
CPE cpe:2.3:a:facebook:meta_spark_studio:*:*:*:*:*:*:*:*
References () https://www.facebook.com/security/advisories/cve-2024-23347 - () https://www.facebook.com/security/advisories/cve-2024-23347 - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Antes de v176, al abrir un nuevo proyecto, Meta Spark Studio ejecutaba scripts definidos dentro de un archivo package.json incluido como parte de ese proyecto. Esos scripts tendrían la capacidad de ejecutar código arbitrario en el sistema como aplicación.
First Time Facebook meta Spark Studio
Facebook

16 Jan 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 18:15

Updated : 2024-01-30 15:09


NVD link : CVE-2024-23347

Mitre link : CVE-2024-23347

CVE.ORG link : CVE-2024-23347


JSON object : View

Products Affected

facebook

  • meta_spark_studio