9.8
CVE-2021-33420
- EPSS 1.61%
- Veröffentlicht 15.12.2022 19:15:15
- Zuletzt bearbeitet 21.04.2025 20:15:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Replicator Project ≫ Replicator Version < 1.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.61% | 0.727 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://advisory.checkmarx.net/advisory/CX-2021-4787
https://github.com/inikulin/replicator/commit/2c626242fb4a118855262c64b5731b2ce98e521b
https://github.com/inikulin/replicator/issues/16
https://github.com/inikulin/replicator/pull/17