7.8
CVE-2024-23347
- EPSS 0.23%
- Veröffentlicht 16.01.2024 18:15:11
- Zuletzt bearbeitet 20.06.2025 18:15:28
- Quelle cve-assign@fb.com
- CVE-Watchlists
- Unerledigt
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Facebook ≫ Meta Spark Studio Version < 176
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.461 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|