CVE-2023-45311

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/10/2023
Last modified:
28/11/2023

Description

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fsevents_project:fsevents:*:*:*:*:*:node.js:*:* 1.2.11 (excluding)