First published: Tue May 26 2020(Updated: )
JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JerryScript | =2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13622 has a high severity due to its potential to cause denial of service through assertion failures.
To mitigate CVE-2020-13622, update JerryScript to version 2.2.1 or later, where the issue is resolved.
CVE-2020-13622 is a denial of service vulnerability affecting JerryScript through improper handling of Proxy object key queries.
CVE-2020-13622 affects JerryScript version 2.2.0; earlier and later versions may not be impacted.
Yes, CVE-2020-13622 can potentially be exploited remotely if an attacker can manipulate Proxy objects within the application.